Governance, in the open

Documents & Policies

This is the live governance library for JonnyAI — the agency, the BizOS platform and the wider software line. Twelve governing policies say what must be true; fourteen standard operating procedures say how it’s done. They are published here because customers in regulated sectors deserve to see how the platform holding their data is actually run — not a summary of it.

Version 1.0 · effective 13 July 2026 · reviewed annually and after any material change. The source of truth lives in version control; this page tracks it.

Governing policies

What must be true, always — security, data protection, AI governance, continuity and the rest.

POL-01Information Security Policy

The whole security posture: least privilege, tenant isolation, mandatory controls across every account and asset.

POL-02Data Protection & UK GDPR Policy

Personal data as controller and processor under UK GDPR — including special category care data, subject rights and breach clocks.

POL-03Acceptable Use Policy

Rules for using company systems, accounts and devices — written so the first collaborator inherits them on day one.

POL-04Access Control & Identity Policy

Who can reach what: BizOS product roles enforced down to the database, and operational access to the infrastructure.

POL-05AI Governance & Responsible AI Policy

How the AI is governed: deterministic engines as source of truth, confirm-steps on every action, data minimisation to models, the HMRC red line.

POL-06Secure Development & Change Management Policy

How code reaches production: the four gates, change classes, standing engineering rules and supply-chain discipline.

POL-07Business Continuity & Disaster Recovery Policy

Keeping the platform and business running: RPO/RTO, continuity scenarios, and the sole-operator contingency.

POL-08Incident Management Policy

Classifying and governing incidents: severity classes, non-negotiable duties, evidence handling and external reporting.

POL-09Supplier & Third-Party Management Policy

Subprocessors and vendors: the authoritative register, selection and exit rules, fail-open vs fail-closed.

POL-10Data Retention & Deletion Policy

How long data lives and how it dies: the retention schedule, deletion standards and the keep-less rule.

POL-11Risk Management Policy

The live risk register: 5x5 scoring, appetite, and escalation rules.

POL-12Marketing Communications & Consent Policy

PECR-compliant marketing: consent-first, tokenised unsubscribe, honest outbound and the platform's own campaign guarantees.

Standard operating procedures

How the work is actually done — onboarding, deployment, incidents, support, billing, offboarding.

SOP-01Client Onboarding & Tenant Provisioning

New BizOS customer or pilot: self-serve and assisted onboarding, DPA discipline, the go-live checklist.

SOP-02Module Development Lifecycle

The strict per-module order from migration to gates, with the governance hooks bound in.

SOP-03Deployment & Release

Shipping to production: pre-deploy gates, the SSH fast-forward deploy, the smoke test and rollback.

SOP-04Database Migrations

Schema changes: numbered, idempotent, RLS on every table, forward-only.

SOP-05Incident Response Runbook

Outage, security event or data breach: first five minutes, containment moves, comms and close-out.

SOP-06Backup & Restore

What is backed up and by whom, the monthly check, surgical and full restores, the annual drill.

SOP-07Customer Support & SLAs

Customer support channels, response targets, working inside tenant workspaces, ticket records.

SOP-08Billing, Subscriptions & Dunning

Stripe events, plan changes, dunning, refunds, reconciliation and the founding-price promise.

SOP-09Secrets & Credential Management

Where secrets live, the register, rotation cadences and guard rails.

SOP-10Client Offboarding, Export & Deletion

Cancellation or deletion request: exports, the 90-day clock, what survives deletion.

SOP-11Agency Engagement Delivery

Any JonnyAI agency project: brief to proposal to delivery rhythm to handover and ownership defaults.

SOP-12Sales, Demo Workspaces & Pilots

New prospect to tailored demo to pilot — the Southernbrook method.

SOP-13AI Actions & Signal Providers

Adding or changing anything JonnyAI can see (signals) or do (actions).

SOP-14Cron & Automation Monitoring

The scheduled automation lines: rules, the weekly check, and runaway containment.

Annexes

Governance for the other trading activities.

Questions about any of these — including data processing agreements for BizOS workspaces — go to hello@jonnyai.co.uk.

See also the customer-facing Privacy Policy and Terms.

← Back to Homepage