Security and data

Know what your AI assistant can access.

A useful NetSuite AI assistant needs clear boundaries. This overview summarizes current public privacy information so administrators can ask the right questions before enabling Carmen.

Your NetSuite role remains important

Business queries are checked under the user’s current NetSuite role. Administrators control Carmen access and enabled account connections. Confirm the role, subsidiaries and record permissions for each intended pilot user before testing a workflow.

Test with a restricted role as well as an administrator. A successful administrator demonstration alone does not show what every employee can access.

Separate the places where information is handled

  1. NetSuite: customer chat and request history may be stored in the customer’s account.
  2. Carmen hosted services: configuration, licensing, usage, security and operational records support service delivery.
  3. The selected AI provider: relevant questions, context and permitted results are processed using the configured provider account.

A request uses the selected provider, not every provider supported by Carmen. Consult the current provider disclosures and your administrator for the setup that applies to your account.

Retention is specific to the service and provider

Provider terms, account settings and retention rules apply. We do not promise zero provider retention. We do not use customer chat or extension data to train our own general-purpose AI models.

Removing an extension or disconnecting an account does not automatically delete existing customer or server records. Deletion can require coordination with an administrator, and backups or legal obligations may affect timing. See storage and retention details.

Review the browser companion separately

Pocket Detective has its own browser permissions and page-context controls. Review the extension notice before installation and use the approved setup process for your account.

The limited-use commitments explain restrictions on extension data use and transfer. The marketing overview does not replace those commitments.

Questions for a pilot review

  • Which users, roles and subsidiaries are in scope?
  • Which provider account processes requests?
  • What history, diagnostics and page context are enabled?
  • Which records and workflows have been validated?
  • Who handles access removal and deletion requests?
  • How will users check answers before acting?

Contact and complete notices

For data-handling questions, email privacy@askcarmen.ai. Read the website and service privacy notice and Pocket Detective privacy notice for the fuller explanation. No system is guaranteed secure.

What would you ask your NetSuite?

Bring one real workflow to a conversation about the limited Carmen beta.

Request beta access