Security is a feature,
not a checkbox.
We treat every byte of your customer data like it matters. Multi-tenant row isolation, zero foundation model training, automated prompt injection defenses, and strict TLS 1.3 encryption by default.
What we actually enforce in production
Encryption
In transit & at restTLS 1.3 / 1.2 in transit, AES-256-GCM encrypted storage at rest for every workspace.
Data isolation
Per workspaceEvery workspace is scoped and isolated. Vector searches enforce tenant-boundary filters.
Zero Model Training
Strict InvariantYour data is never used to train, fine-tune, or improve commercial base models.
Six layers of physical and logical security
Encryption everywhere
Strict TLS 1.3 across all HTTP and WebSocket SSE connections, with AES-256 encrypted credential storage.
Workspace isolation
Every workspace is a separate, scoped tenant. Cross-workspace data access is mathematically impossible.
Strict access control
Role-based access boundaries ensure only verified workspace members can access knowledge bases.
Rotating session tokens
Short-lived access tokens with rotating cryptographic refresh tokens and SHA-256 session hashing.
Prompt injection defenses
Delimited XML fences and automated heuristic sanitization prevent prompt injection and model jailbreaks.
No training on your data
Your content is used strictly in ephemeral RAG context windows to answer your visitors and nothing else.
Your data is strictly yours.
We do not train foundation models on your content. We do not sell data. We do not use it for anything other than answering your visitors. When you delete a workspace, every chunk, vector, and transcript is purged within 30 days.
Test it on your own website in under 2 minutes.
Enter your domain to index your pages and preview live answers.