Secure AI project management, approval-first by design
The reason most PMOs stall on AI is not capability, it is governance: where does the data go, who approved that email, and can we prove it later. Pocket PMO answers all three. Your data is never used to train models, the AI never acts without an explicit human approval, and every action is written to an audit log.

Approval-first AI
The AI drafts and proposes. It never updates a register, sends an email or changes a date until a person approves it.
Never used for training
Requests run through a secure AI gateway to enterprise providers with training and retention disabled.
Encrypted throughout
AES-256 at rest, TLS 1.3 in transit, for both application data and AI requests.
Tenant isolation
Row Level Security on every business table, enforced in the database rather than in application code.
Audit trail
Every AI proposal, approval, rejection and data change is recorded with who, what and when.
GDPR position
UK/EU-focused handling, documented sub-processors, self-serve export and deletion.
What "approval-first" actually means
Plenty of tools describe AI that "takes action for you". For a PMO, that is the problem rather than the feature. An agent that quietly reclassifies a risk, moves a milestone or emails a sponsor has removed the audit trail that governance depends on.
In Pocket PMO the AI produces proposals. A drafted status report, a suggested risk mitigation, a proposed replan, a meeting invitation — each arrives with its reasoning attached and two buttons: approve or reject.
- No silent writes. Registers, plans and budgets change only through an approved action or a person editing directly.
- No unapproved outbound. No email, invitation or shared report leaves the system without a human pressing send.
- No invented data. Where the AI has no project evidence, it says so and logs the open question rather than filling the gap.
- Everything recorded. Approvals and rejections are audit entries, so a reviewer can reconstruct who decided what.
The full behavioural commitments are in the AI policy.
Where your project data goes
AI requests are sent over TLS 1.3 to enterprise AI providers through a secure gateway. The gateway is configured so customer content is not retained by the provider and is not used to train models — that applies to reasoning, summarisation and image generation alike.
Your project data itself stays in the application database, encrypted at rest with AES-256, isolated per organisation by Row Level Security evaluated in the database. Sub-processors are listed publicly, so procurement can review them without asking. See the sub-processor list and the security overview.
Enterprise-grade AI PMO governance controls
- Identity — email and password screened against known-breached credentials, Google and Apple sign-in, SAML SSO on request.
- MFA — TOTP multi-factor authentication with step-up on sensitive actions.
- Sessions — 30-minute inactivity timeout with a warning before expiry.
- Roles — organisation roles stored separately from user profiles and enforced server-side, so permissions cannot be changed from the browser.
- Shared reports — snapshots default to invited access with one-time codes, and can be revoked immediately.
- Audit pack — export the full audit history for a project in one click when an auditor asks.
- Abuse protection — authentication, AI usage and public intake forms are rate-limited and validated.
GDPR-compliant AI reporting
Reporting is where personal data usually leaks: a status report pasted into a public chatbot, a resource sheet emailed outside the organisation. Because report generation happens inside the platform, the data never leaves the governed path, and the resulting report carries an access model rather than being a loose attachment.
On the data-subject side, individuals can export their data and request deletion from within the product, and deletion removes the account and its content rather than flagging it. Details on the privacy notice and Trust Centre privacy page.
What we do not claim
We are not certified to SOC 2 or ISO 27001. Cyber Essentials is the first target. If either certificate is a hard procurement requirement today, we will tell you so rather than imply otherwise — and you can raise it directly through Trust Centre contact.
Live service status and the security roadmap are published at status and roadmap.
Frequently asked questions
Is our project data used to train AI models?
No. AI requests run through a secure gateway to enterprise providers configured so customer content is neither retained by the provider nor used for model training.
Can the AI change our project data or send emails on its own?
No. Pocket PMO is approval-first: the AI drafts and proposes, and a person must approve before any register, plan, date or outbound message changes. Approvals and rejections are recorded in the audit log.
How is one organisation kept separate from another?
Row Level Security is enabled on every business table and evaluated in the database using role helper functions, so isolation is enforced below the application rather than by application code alone.
Do you hold SOC 2 or ISO 27001?
Not today. Cyber Essentials is our first certification target. We publish what we do and do not hold in the Trust Centre rather than implying certification we have not achieved.
Is Pocket PMO GDPR compliant?
We operate to GDPR: documented sub-processors, encryption in transit and at rest, self-serve data export and deletion, and audit logging of data changes. The privacy notice sets out lawful bases and retention.
Can we restrict who sees a shared report?
Yes. Snapshot reports default to invited access using six-digit one-time codes, trust a browser for 30 days, and can be revoked immediately. Fully public links remain available where the content is not sensitive.
What happens if the AI does not know something?
It states that no project data exists rather than inventing a figure, and logs the unanswered question as a project action so a person can supply the answer.
See Pocket PMO in action
Try the interactive demo or start a free 15-day trial — cancel anytime.
