Security and data privacy

Our products are built for organizations whose data cannot leave their perimeter. This page explains exactly what that claim means.

Our principles

  • Data never leaves your perimeter

    All processing runs on your own infrastructure. No request reaches an external service unless you explicitly enable it.

  • We never train on your data

    Data belonging to your organization is never used to train or improve models. This is a contractual commitment, not a setting.

  • Enterprise access control

    Centralized authentication, role-based access and the option to connect your existing directory for user management.

  • Everything is audited

    Every query, document access and configuration change is written to an audit log your security team can export.

Deployment models

Three options, and the choice is yours. They differ in where data lives and who operates the system.

Deployment modelsWhere data livesOperated by
On-premiseEntirely in your own data center. Both data and models stay inside your perimeter.Your data centerYour team, with our support
Dedicated cloudA separate, dedicated instance for your organization on domestic cloud infrastructure.Domestic cloud, dedicated instanceOur team
Air-gappedFor organizations whose network has no external connectivity. Updates are applied offline.Your isolated networkYour team

Technical practices

  • Encryption in transit over TLS and at rest on disk
  • Full tenant data isolation in multi-organization deployments
  • Least privilege for our staff; access to your environment only with explicit, logged approval
  • Security code review and dependency scanning in the release pipeline
  • Regular backups with point-in-time recovery
  • Data retention per your policy, with deletion on request

Frequently asked questions

Is our data sent to external services?
No. On-premise and air-gapped deployments generate no outbound traffic. If your organization chooses to use an external model, that is an explicit decision you can turn off.
Do the models train on our data?
No. Your data is used only to answer at request time and is not retained for training.
Who on your team can access our environment?
Nobody by default. Support access is temporary, scoped to a named individual, fully logged, and revoked when the work ends.
What happens to our data if we stop working together?
On-premise, the data was always yours. In a dedicated cloud, data is deleted on the agreed schedule and we issue a deletion certificate.
Do you hold security certifications?
We present our current certification status and compliance documentation in the technical session. If you have a specific requirement, raise it before we start.

Have a specific security question?

Our technical team answers directly. If you have a security questionnaire, send it over.

Talk to our technical team