Security & privacy

Built for teams that hold other people’s data.

Isolation, provenance, and privacy are part of the substrate—not features bolted on after procurement asks.

Tenant scopedSensitivity awareAuditable by design
Request traceISOLATED
tenant_idagency_7F2Abusiness_id · acme_fitness
Tenant-scoped request
Business workspace
Sensitivity classification
Model routing
Citation store
Human review
7Audit history
Cross-tenant request403 · DENIED

Control inventory

Foundation now.
Roadmap labelled honestly.

Current, preview, and planned controls stay visibly separated so teams can assess what exists today.

01
Current

Multi-tenant isolation

Every database query is tenant-scoped. Cross-tenant access is denied without leaking whether a resource exists.

02
Current

Per-business blob isolation

Uploaded files use per-business paths with traversal and symlink guards.

03
Product preview

Sensitivity-aware routing

High-sensitivity sources can route to a local model so content stays inside your infrastructure.

04
Product preview

Data-erasure cascade

A gated forget-customer action removes artifacts, insights, briefs, and proposals.

05
Current

Auditability

Model calls record provider, model, tokens, cost, and verification incidents.

06
Planned

Self-hosting

Run the stack with local-model routing and internal deployment controls.

Proven, not promised

Isolation you can point to.

Foundation controls are enforced in the substrate. Product-layer controls remain clearly labelled.

403Cross-tenant access denied
HIGH → localSensitivity routing path
100%Model calls designed to be logged

Security whitepaper

Inspect the isolation model in detail.

A technical walkthrough of tenancy, routing, erasure, and audit guarantees is available on request.

Request the whitepaper

Isolation you can prove to your clients.

Follow one source from raw conversation to a campaign claim your team can defend.