Security
What is actually in place, and what isn't.
Two lists. The second one is longer than we would like, and publishing it is cheaper for both of us than having you discover it in week six.
In place today
Nine controls we can describe precisely.
Workspace isolation
The workspace is the tenancy boundary and it scopes all data and all keys — documents, chunks, entities, assertions, provenance, the ontology. There is no cross-workspace read path because there is no cross-workspace query.
Scoped API keys
Keys belong to one workspace and carry the ingest scope, the search scope, or both. A key used outside its scope is refused with the scope it lacked named in the response.
Rotation and revocation
Issue, rotate and revoke keys yourself from the console, with no support ticket. The plaintext is shown exactly once at creation and is not retrievable afterwards.
Single sign-on
Identity runs through WorkOS AuthKit with sealed sessions. Directory sync is bidirectional over webhooks, with just-in-time provisioning.
Immediate session revocation
Removing someone from an organisation revokes their live sessions rather than waiting for a token to expire. There is also a global per-user kill switch.
OAuth for machine clients
MCP clients authorise as a specific person over OAuth 2.1 bearer tokens and can do no more than that person could. The tool surface is build-enforced to match the published API exactly.
Retrieval audit trail
Every search is persisted with its origin stamped by the auth guard — API key, console, or MCP — plus the query, the mode, per-step timings and the answer produced.
Encryption in transit and at rest
TLS on every endpoint, and managed encryption at rest on the datastores. Keys are managed by the cloud provider, not by you.
We hold nothing we were not sent
No crawler, no pull-based connector, no credentials to anything of yours. Everything we store is content you pushed to an endpoint.
Not in place
Eight things we do not have.
If any of these is a requirement rather than a preference, we are not the right choice yet and we would rather tell you here than on a call in six weeks.
SOC 2 Type II
Not certified, and no audit currently in progress. If your procurement requires it, we will not clear that bar this year.
HIPAA / BAA
We will not sign a business associate agreement, and the service should not be used for protected health information.
Bring your own cloud
One managed deployment. No installation into your VPC or your cloud account.
Customer-managed keys
Encryption keys are provider-managed. You cannot supply or rotate your own.
Regional data residency
A single region. No EU-resident option today, which is a hard blocker for some buyers and we would rather say so early.
Model choice or region
Extraction, embedding and synthesis run on models we select, in the regions those providers run. You cannot pin either.
Full administrative audit log
Search activity is logged in detail. A complete audit trail of every configuration and membership change is not yet exposed.
Penetration test report
No third-party test has been commissioned. We are not going to describe an internal review as one.
FAQ
Frequently asked
The questions a security review actually asks.
Send us the questionnaire.
We will answer it as directly as this page. If something on the second list blocks you, say so and we will tell you honestly whether it is close.