Skip to main content

IDEA (Isolated Document Environment Agent) FAQs

AWS Cloud Security

General

Open all

    IDEA (Isolated Document Environment Agent) is an enterprise-grade AI solution that gives each user a secure, private environment to store documents and ask natural language questions about them. Think of it as a personal AI research assistant — one that only ever analyzes each user’s own documents, with no risk of cross-user data exposure.

    IDEA is designed for organizations that need to provide AI-powered document search and Q&A to multiple users while maintaining strict data privacy between those users. It is particularly well-suited for executive teams, boards of directors, legal and compliance departments, financial teams, and any group that handles sensitive, role-specific documents.

    Professionals spend an estimated 10–20 hours per month manually searching through documents for specific information. IDEA eliminates that burden by letting users ask plain-language questions — like "What were our Q4 financial results?" or "What action items came out of the last board meeting?" — and receive instant, cited answers drawn from their own document library.

    Unlike general-purpose AI assistants, IDEA answers based exclusively on documents that the user has referenced for use. It is disconnected from the world wide web and therefore does not hallucinate facts from general training data — it retrieves and summarizes information directly from your organization's own files. Each user's document library is completely isolated from every other user's.

Security & Privacy

Open all

    IDEA enforces strict user-level isolation at multiple layers. Documents are stored in individually partitioned storage prefixes per user. Access control lists (ACLs) are automatically generated and enforced at query time, so the AI engine only retrieves documents the authenticated user is authorized to see. This isolation is verified through automated testing as part of every deployment.

    Yes. IDEA uses KMS (Key Management Service) encryption for all data at rest, and TLS 1.3 for all data in transit. Your documents never leave your own cloud environment.

    All data remains within your own AWS account and your selected AWS region. IDEA does not transmit your documents to any third-party systems. You retain full ownership and control of your data.

    No. User conversations and queries are explicitly not logged, protecting the privacy of every interaction. Only technical sync job logs (related to document indexing) are recorded for operational purposes.

    IDEA is built on AWS Q Business, which is SOC 2 certified. The solution supports GDPR data residency controls, can be configured for HIPAA compliance, and includes configurable data retention policies (default: 365 days). Organizations should consult their legal and compliance teams for specific requirements.

    Yes. IDEA uses AWS IAM Identity Center for authentication, which supports optional MFA (multi-factor authentication) for all users.  It can also support any SSO production/solution that works with Q Business or IAM Identity Center.

Capabilities & Features

Open all

    Users can:

    • Ask natural language questions about their documents ("Summarize the last board meeting")
    • Get cited answers that reference the source document
    • Review conversation history within a session
    • Access the interface from any web browser — no app installation required

    IDEA works best with PDF and DOCX files, which support native text extraction. It also supports plain text files and other common document formats. For best results, documents should contain searchable text (not scanned images without OCR).

    Yes. IDEA supports both shared documents (accessible to all subscribed users — ideal for company-wide policies, board minutes, or reports) and private documents (accessible only to a specific individual). Administrators control which documents are shared and which are private at upload time.

    Documents are typically indexed and searchable within 2–5 minutes of upload. Administrators can also trigger an immediate sync for time-sensitive uploads.

    IDEA supports 50+ concurrent users out of the box. It is designed to scale linearly — adding more users simply requires subscribing them to the application.

Deployment & IT

Open all

    A complete deployment — from prerequisites to a fully tested, production-ready system — takes approximately 30 minutes. The deployment is largely automated via a single script that provisions all required cloud infrastructure.

    IDEA deploys entirely within your existing AWS account. It requires an AWS account with administrative access, the AWS CLI, AWS SAM CLI, and Python 3.12 or newer. No additional hardware or on-premises infrastructure is needed.

    Minimal. Day-to-day operations consist of adding users, uploading documents, and monitoring standard cloud health metrics. The solution includes pre-configured automated alerts for both operational and security events, so your IT team is notified proactively if anything requires attention.

    IDEA can be deployed in four AWS regions: US East (N. Virginia), US West (Oregon), Europe (Ireland), and Asia Pacific (Sydney).

AI Accuracy & Responsible Use

Open all

    IDEA retrieves answers directly from your uploaded documents and provides source citations with every response, allowing users to verify the information. The system includes hallucination mitigation features that are automatically configured during deployment.

    Important disclaimer: IDEA is an information retrieval and document summarization tool designed to support decision-making. It is not a substitute for human judgment. All AI-generated responses should be independently verified and should not serve as the sole basis for governance, financial, or legal decisions.

    IDEA will indicate that no relevant information was found rather than generating a speculative answer. This behavior is by design — the system is grounded in your documents, not general AI knowledge.

    Yes, with appropriate configuration. IDEA supports HIPAA-eligible configurations and GDPR data residency controls. Organizations in regulated industries should work with their compliance teams to validate the configuration against their specific requirements.

Getting Started

Open all

    Contact your solution provider to receive the IDEA deployment package. From there, your IT administrator can complete the full deployment in under 40 minutes using the included automated deployment script and step-by-step Customer Deployment Guide.

    IDEA includes comprehensive documentation (Deployment Guide, Quick Start Guide, and technical README). For deployment issues, your solution provider offers technical support. AWS Support is also available for underlying cloud service questions.

Did you find what you were looking for today?

Let us know so we can improve the quality of the content on our pages