Trust · Security architecture
Security architecture
The same controls that make an answer trustworthy, access control, grounding, and audit, are the security model. This page describes the shape of that model. The configuration detail, the diagrams, and the control settings are in the security pack.
An isolated landing zone
Each deployment runs inside a governed landing zone with a security baseline enforced from the start: audit logging on, threat detection on, public access to storage blocked, encryption at rest and in transit required, not optional. Environments are separated so that a failure in one cannot reach another. The blast radius of any single fault is contained by design.
Two tenancy models, selected per customer
Your environment runs on infrastructure provisioned for you alone.
Which model fits depends on your regulatory frame, your data classification, and your deployment choice. It is selected with you during discovery, not defaulted.
Identity is yours, federated
Users sign in with your corporate credentials through standard federation (OIDC and SAML). Access is enforced at retrieval: what a user is entitled to see decides what the system can retrieve for them, so restricted content cannot surface in an answer to someone who should not have it. Multi-factor authentication is supported, and offboarding is a single action with hard revoke, so access does not linger after someone leaves. The same access model applies on every surface the platform offers.
Private connectivity to model inference
Traffic between the platform, your documents, and model inference moves over private network paths rather than the public internet. Storage rejects unencrypted connections and blocks public access. The result: your documents and the model reasoning about them never meet on an open network.
Adversarial testing, run daily
We attack our own system so you do not find out what an attacker would have. Adversarial tests run daily, per tenant and per model. Testing coverage and results are available during the security review, and findings feed directly back into guardrail defaults.
Your controls, not a rebuild
Where you already run governance, identity, data loss prevention, network policy, we adopt the controls you have rather than asking you to rebuild them inside our tool.
The full detail is in the pack
We publish the shape and the guarantee here. The settings, screens, and parameters are in the security pack, where a reviewer can check them against your own control framework.
Get the security packEvidence for your review
Get the security pack
For security reviewers and vendor risk teams. The pack contains the four ISO certificates with their full scope statements, the architecture diagrams, and the data processing agreement. The Statement of Applicability is included in the pack; it is not published on the site.