Security

The page your IT lead reads before saying yes.

Every claim here maps to a specific control on the platform. Nothing is aspirational.

Four controls

Where the protection actually sits.

Threat protection at the edge

  • Distributed attacks absorbed before they reach the platform
  • Automated bots and scanners filtered out
  • Rate limits on every entry point
  • Managed rules against known attack patterns

Encryption end to end

  • Encrypted from your browser to the last service, not only to the front door
  • Modern protocols, strict transport security, top-grade configuration
  • Certificates renewed automatically
  • Security headers on every response

Access and least privilege

  • Single sign-on in front of admin surfaces
  • Roles decide who sees which documents
  • Each service can reach only what it needs
  • Audit trail of who did what

Isolation and recovery

  • Every service isolated on its own network segment
  • Data persisted and backed up, versioned and offsite
  • Restore procedures tested, not assumed
  • Images and operating systems patched on a schedule
Operating rules

Six habits, kept every day.

End-to-end protection

Users to the edge to the platform. Encrypted everywhere.

Attack protection

Bot filtering, rate limiting, managed rules.

Least privilege

Single sign-on. Service-to-service isolation.

Regular backups

Databases, volumes, and files. Offsite and versioned.

Monitoring and alerts

Health checks and logs on every service. Alerts before users notice.

Updates and patching

Images, operating systems, and security updates on a cadence.

Questions your IT lead will ask

Straight answers.

Where does our data live?

On dedicated infrastructure provisioned for your platform. Documents, conversations, and indexes stay there. Model providers receive only the text needed to answer a question, under their enterprise terms.

Can model providers train on our data?

No. The platform uses provider endpoints with training disabled and can be pointed at private model deployments where required.

Who can see what?

Roles and document permissions are set by your admin. A person only receives answers from documents they are allowed to read.

What happens if a server fails?

Data is persisted and backed up. Restore is a tested procedure with a defined recovery time, agreed during onboarding.

Can we audit it?

Yes. Usage, access, and model activity are logged and available to your admin, and we will walk your security team through the architecture.

Have your security team talk to ours.

Request access We will walk through the architecture and answer the hard questions.