Trust
Security, privacy, and compliance are built into the operating loop, not bolted on. Here's what to expect.
Security Posture
TLS 1.2+ in transit. AES-256 at rest. Customer-managed keys available.
SSO/SAML 2.0 with SLO (Okta, Azure AD), SCIM 2.0 provisioning, MFA (TOTP) with brute-force lockout, RBAC, role-based ownership across Programs → Projects → Teams.
Multi-tenant by design. Strict data isolation enforced at every query. Deny-by-default authorization with full permission audit.
Hash-chained AuditLog: every record action and privileged operation is versioned with actor, timestamp and tamper-evident chain hash.
Data Sovereignty
Route AI workflows to your preferred provider, including private, on-prem, or VPC-deployed models. Your prompts never train shared models.
Deploy in the region that matches your residency obligations. Data does not leave the region without your explicit consent.
Your records, prompts, and generated artifacts are yours. Nothing is used to train models, ours or anyone else's.
Compliance Frameworks
Evidence is produced continuously from the Persisted Knowledge Graph, not reconstructed during audit.
Policies
Talk to our team about your compliance, residency, and procurement requirements.
Talk to Trust Team