Security and trust

Built for live events where trust matters.

This page is written for IT, security, data protection and procurement teams. It states what ReactLive does, and it does not claim certifications or guarantees we cannot evidence.

01 · How the AI behaves

AI should not make your event less predictable.

The rules the agents follow, in brief. Each links to where it is explained in full.

Controlled per agent, per event
Each agent is set to Off, Assist or Auto. The default is recommendation, not action. Control model
Humans outrank agents
A deliberate human decision is not quietly reversed, and operators can move any agent to Assist or Off during a live event. Human authority
No source, no automatic answer
Answers are grounded in event material, cite their source, and low confidence never publishes automatically. How Answer works
Holding, not silent deletion
Protect holds content before publication and records why; held content stays visible and reversible. How Protect works
Safe failure, disclosed AI
If something cannot be evaluated confidently it goes to a person, and AI output is always labelled as AI.
02 · Data boundaries

What the agents use, and what they do not.

Agents operate on event data

  • Contributions submitted to that event — questions, poll responses, reactions, ratings
  • Event configuration: moderation rules, tone, agent modes
  • Event knowledge you supplied for that event
  • Activity signals: votes, participation, timing

Agents do not browse for answers

  • Answer does not answer from the open internet
  • Agents do not read documents you did not supply to the event
  • No agent acts on another event’s data
03 · Roles and permissions

Not everyone running an event needs every control.

Access is scoped by role and by event, so a moderator brought in for one event does not gain the run of the account.

Admin
Configures events, agent modes, event rules, knowledge, and who has access.
Moderator
Works the queue, approves agent suggestions, handles held content.
Presenter
Sees the questions to answer, without the operating controls around them.
Event-level scope
Permissions apply to an event rather than globally, so access can be granted for one event and end with it.
04 · Audit trail

AI activity is visible, not inferred.

If an agent influenced what an audience saw, that should be inspectable afterwards without anyone reconstructing it from memory.

  • What an agent suggested
  • What it did, and in which mode
  • Why it acted — the rule or source behind the action
  • Confidence, where relevant
  • What required human approval, and who approved it
  • Moderation outcomes, including releases and rejections
05 · Authentication

Getting the right audience into the event.

Operator access
How event team members sign in.
Enterprise SSO
Protocols and providers supported.
Audience access
Open link, restricted link, or authenticated access.
06 · Data retention

How long event data is kept.

Detailed documentation is available on request for your security and procurement review — contact us.

07 · Data residency

Where event data is processed and stored.

Detailed documentation is available on request for your security and procurement review — contact us.

08 · AI providers

Which models see event content.

Detailed documentation is available on request for your security and procurement review — contact us.

09 · Compliance

We list certifications we hold. Nothing else.

If your procurement process needs documentation we have not published, contact us and we will tell you what exists today rather than what we intend to have.

Bring your security questions early.

We would rather answer them before a pilot than during one.