An AI teammate that knows the deal has to read the deal. Calls, email threads, calendar invites, Slack messages, CRM records. The context that makes Molly useful is the same context a security team is paid to protect: pricing conversations, legal redlines, named champions and blockers, commercial terms that have not been signed yet.
There is no version of the execution layer that runs on less than that. Strip the context back and the guidance degrades into generic advice, which is exactly where reps already are when they paste a transcript into a chat window.
So security is not a compliance exercise running alongside the product. It is a condition of the product working at all. ISO 27001 and CASA are the independent confirmation of an architecture that was designed this way from the first line of the context pipeline.
ISO 27001 is the international standard for information security management. It is not a statement that a company takes security seriously. It is an external audit of whether the controls exist, are documented, are actually followed, and are reviewed on a schedule.
Access control. Encryption in transit and at rest. Incident response. Supplier risk. Change management. Business continuity. Each one with evidence attached, assessed by an auditor who examines the evidence rather than the intention, and re-examined on a recertification cycle.
For a revenue leader running Overpath through procurement, that removes a whole category of question from the process. The certificate answers it before the security questionnaire arrives.
ISO 27001 covers how Overpath operates as a company. CASA covers what happens at the point where Overpath touches your data.
CASA - Cloud Application Security Assessment - is the framework run through the App Defense Alliance. Applications requesting sensitive or restricted access to Google Workspace data are assessed against it. Overpath reads Gmail, Google Calendar, and Google Meet. That access is what lets Molly see the thread where a deal went quiet and the invite where the economic buyer quietly dropped off the call. It is also precisely the access that should be verified by someone other than the vendor requesting it.
CASA verification means the application has been tested against the framework: how data is handled once it is retrieved, how credentials and tokens are stored, how the application behaves at its authentication and API boundaries. Assessed independently. Not self-attested.
Customer data is EU-resident. Processing is GDPR compliant. Data is encrypted in transit and at rest. Agentic actions are auditable, so a manager can see what Molly did, when, and on whose approval.
Customer data is never used to train models. Not ours, not anyone else’s. This is the commitment that separates a purpose-built execution layer from a general-purpose chat interface, and it is the reason the workaround was never a real option for enterprise revenue data.
Security review is where most AI sales tooling stalls. A rep finds a tool, a team runs a pilot, the value is obvious, and then the whole thing meets a RevOps leader or a CISO who asks where the data goes and receives an answer nobody is comfortable writing down.
That is not a procurement problem. It is a design problem surfacing late. A platform that ingests the unstructured truth of a deal and then acts on it has to be built for enterprise data governance from the beginning, because retrofitting it means rebuilding the context pipeline.
Overpath was built that way. The certifications say so out loud.
A certificate is a floor. It confirms that a set of controls was in place and functioning at the point of assessment, and that the organisation has a system for keeping them that way. It does not end the work. Recertification, penetration testing, supplier reviews, and incident drills continue on their own cadence, and the scope expands as the platform does.
That is the honest shape of security in a company handling live commercial data. Verified, reviewed, and never treated as finished.
Revenue teams are handing AI systems the most sensitive information their companies hold. The market has moved faster than its own governance, and reps are filling the execution gap with tools that were never designed to hold enterprise data to an enterprise standard.
The execution layer for revenue teams holds it to that standard. ISO 27001 and CASA are how that gets proven rather than claimed.