Skip to content

Security is a feature,
not a checkbox.

We treat every byte of your customer data like it matters. Multi-tenant row isolation, zero foundation model training, automated prompt injection defenses, and strict TLS 1.3 encryption by default.

Core Invariants

What we actually enforce in production

Encryption

In transit & at rest

TLS 1.3 / 1.2 in transit, AES-256-GCM encrypted storage at rest for every workspace.

Data isolation

Per workspace

Every workspace is scoped and isolated. Vector searches enforce tenant-boundary filters.

Zero Model Training

Strict Invariant

Your data is never used to train, fine-tune, or improve commercial base models.

Technical Controls

Six layers of physical and logical security

Encryption everywhere

Strict TLS 1.3 across all HTTP and WebSocket SSE connections, with AES-256 encrypted credential storage.

Workspace isolation

Every workspace is a separate, scoped tenant. Cross-workspace data access is mathematically impossible.

Strict access control

Role-based access boundaries ensure only verified workspace members can access knowledge bases.

Rotating session tokens

Short-lived access tokens with rotating cryptographic refresh tokens and SHA-256 session hashing.

Prompt injection defenses

Delimited XML fences and automated heuristic sanitization prevent prompt injection and model jailbreaks.

No training on your data

Your content is used strictly in ephemeral RAG context windows to answer your visitors and nothing else.

Your data is strictly yours.

We do not train foundation models on your content. We do not sell data. We do not use it for anything other than answering your visitors. When you delete a workspace, every chunk, vector, and transcript is purged within 30 days.

GDPR & CCPA Ready
EU Standard Contractual Clauses
AES-256 Storage at Rest

Test it on your own website in under 2 minutes.

Enter your domain to index your pages and preview live answers.

https://
No credit card required2-minute automated setupEmbed with one line