Security

Clear the review. Keep the deal moving.

Give security and procurement plain answers: where data lives, who holds the keys, and how every AI call can be traced.

Data boundary

Engine inside the buyer’s cloud

Your product calls the engine. The engine reads and writes only in that cloud account — not a shared SaaS pool.

web

Your app

Your brand

cloud_lock

Customer cloud boundary

Customer cloud

hub

You Can Ask

document_scannerDocument scanning
manage_searchSearch
psychologyAI models
fact_checkAudit logs
cloudTheir infrastructure

keyCustomer-owned keys & storage

What you can promise

The questions that usually block deals

Short, contract-ready answers for CISO and procurement — not slogans.

key

Buyer holds the keys

Encryption keys and service accounts stay in the customer’s cloud. We don’t hold production keys unless the contract says so.

storage

Documents stay put

Files and search indexes live in dedicated storage on that project. No shared document pool across customers.

shield

One customer, one boundary

Each deployment gets its own cloud project or isolated environment. No cross-customer data paths.

visibility

Every AI call is accountable

Security can see what was asked, which documents were used, and what went to the model.

Isolation

Separate by design

Dedicated access, encryption, and network paths for every customer deployment.

security

Least-privilege access

Dedicated service accounts per stack. Deploy automation scoped only to that customer’s project.

key

Encryption you control

On Dedicated Stack, customer-managed keys for databases and file storage — rotated under the buyer’s policy.

swap_calls

Integrations stay private

ERP and internal systems connect inside the customer network. Sensitive domain data doesn’t transit our infrastructure.

Proof

Trace every answer

From the user’s question to the document source to the model response — ready for review.

history

Full request history

Every chat logged with time, user context, and tool calls — exportable when compliance asks.

description

Answers with sources

Responses point back to the document passages used, so reviewers can verify what the model saw.

verified_user

Approved content only

Answers come from indexed company documents — not the open web. You decide what enters the index.

Bring this to the security review

  • task_altDedicated cloud project per customer instance
  • task_altCustomer-owned encryption keys and secrets
  • task_altNo shared document or vector storage across customers
  • task_altAudit trail on model and retrieval calls
  • task_altNetwork egress under the customer’s cloud rules
  • task_altGrounded answers from approved documents only

Walking a security questionnaire?

Book an architecture review — we map VPC, secrets, and data flow against the reference deployment.