Skip to content
PageMax
Get access

How the system is governed.

PageMax puts AI to work for regulated professionals, so the platform is built around control: a named person approves every change, every action lands on a record that cannot be quietly rewritten, and the machine works inside hard limits on what it can see and spend. This page sets out those rules plainly.

Nothing publishes without a named person at your firm.

Every change, whether the system proposed it or someone at your firm asked for it, is staged as a draft first. A question is answered on the spot; anything that would alter your website becomes a proposed change that shows exactly what it will do before it does anything. If a request is unclear, the system asks before it acts. It never guesses.

That draft then waits for a named solicitor at your firm. The approval is recorded with the name and the time, and the gate cannot be skipped: not by PageMax, and not by a firm admin in a hurry.

A record that cannot be quietly rewritten.

Every action on the platform is written to a tamper-evident audit ledger. Each entry is chained to the one before it, so altering an old row breaks the chain after it. History stays history.

Every request is logged end to end: who asked, what was done, when, and the before and after. When a change goes live, the dashboard tells you and links straight to the live page, and the month's activity is laid out in a plain-English Work log where every line is a real, recorded action.

That accountability includes us. When PageMax support views a firm's dashboard, the view is read-only, and both entering and leaving are stamped to the same ledger.

One person, one login, two factors.

Every sign-in requires a second factor from an authenticator app, so a stolen password alone gets nobody in. One-time recovery codes and an administrator reset mean a lost phone never locks anyone out for good.

Each person at the firm has their own login, activated by a single-use link where they set a password only they know, and each sees only what their role needs. The firm manages its own logins, handing them out, reissuing them and switching them off itself, with no vendor in the loop.

Firm data stays with the firm. Assign an enquiry to a solicitor and from that moment only that solicitor can see it. The engine that answers questions about your numbers reads through a locked-down connection that returns zero rows for any firm but yours, and one firm's data is never used for another.

EU infrastructure. GDPR treated as a hard gate.

PageMax runs on EU-located infrastructure, with database and file storage in Frankfurt. Enquiry data sent to a firm through its website belongs to that firm; we process it on the firm's instructions under a data-processing agreement.

An injury enquiry is health data, and the platform treats it that way by construction. The reporting engine can read counts and outcomes but is technically blocked from ever touching names, emails or phone numbers, and when the system learns from what prospective clients keep asking, it works from de-identified question themes, never the raw enquiry. Sensitive enquiry data is redacted and aged out on a schedule, so the firm stays on the right side of GDPR without anyone minding a calendar.

The AI works inside hard ceilings.

Every AI action carries a hard cost cap per call, a daily run cap, and an emergency stop, so no run can run away. Each firm also has a monthly ceiling on AI spend, and the platform refuses new work when it is reached. Every vendor cost is logged per firm, which means we always know exactly what the platform spends, and on whose behalf.

Where we stand.

PageMax is an early-stage Irish company and holds no ISO or SOC certification today. We publish how the system is governed instead. Everything on this page describes controls that are running now, not a roadmap.

The strongest reassurance we can offer is the way the system is built. The second strongest is that you can ask us anything about it.

Get access