Security you can verify.Proven, not claimed.
What a security questionnaire asks for is here — with status. What we do not have is here too.
We are launching soon — secure one of the first spots.
Security per organisation
Two-factor requirement, IP allowlist, session length, SSO and SCIM — settings the owner sets and the audit log records.
An organisation's security settings: two-factor requirement, SSO, SCIM, IP allowlist and session length, all switched on; only the owner changes them.
Audit log without content
Who changed what and when: roles, approvals, settings. Never a chat, never a file.
An organisation's audit log: four entries with time, person and action — role changed, agent approved, sovereignty level relaxed, connection allowed; never content.
What applies — with status
Every row is a statement we can back in the product. "Active" means live for every organisation; "Internal" means done, but without external proof.
Tenant isolation and permissions
- Every route, action and tool passes one central permission check — no scattered logicActive
- Row-level security in the database separates organisations at the database layer as wellActive
- Admins never see their members' chat content — only aggregated usageActive
- There is no "view as user" modeActive
Identity and access
- Two-factor authentication per person; organisation-wide requirement set by the ownerActive
- Single sign-on via SAML and OIDCActive
- Automatic account creation and deactivation via SCIM 2.0Active
- IP allowlist, session length from 1 hour to 30 days, organisation-wide sign-outActive
- Organisation audit log: roles, approvals, settings — never contentActive
- Rate limits on sign-in and keys, fail-closedActive
Encryption and operations
- TLS on every connectionActive
- Storage encrypted at the host; backups additionally client-side with AES-256Active
- Point-in-time backups, daily, 14 days — with a weekly automatic restore testActive
- Security headers (HSTS, framing denied, content security policy) enforced by testActive
- Availability monitoring and self-hosted error tracking — no US servicesActive
- Emergency brakes: maintenance mode, generation stop, global spend capActive
Deletion, data, contract
- Hard delete: single chats immediately, accounts immediately, organisations completely after 30 daysActive
- Retention periods per organisation, enforced nightlyActive
- Export of your own chats, files and notes as JSON, Markdown and ZIPActive
- We train no models on customer dataActive
- Data processing agreement with a named subprocessor annex and objection periodActive
Supply chain and testing
- Dependency and container scans weekly and on every changeActive
- Software bill of materials (SBOM) per buildActive
- Secret scan in the build pipelineActive
- Penetration tests against a throwaway instance before every major change — by usInternal
AI-specific
- Deterministic check layer at the trust boundaries: foreign content from files, web search and tools is data, never instructionsActive
- Tool allow-lists per connection and per automation, fixed on creationActive
- AI usage policy, approval lifecycle for agents and an AI system registerActive
- Marking of AI-generated content under Art. 50(2) AI Act — in the file, not only in the pictureActive
- Sovereignty level per organisation, stepping up only by the owner with an audit entryActive
Active: live in the platform · Internal: by us, without external proof
What we do not claim
A trust center is worth only as much as its gaps. We know these.
- No ISO 27001 certification
- No SOC 2 report
- No external penetration test — our tests are internal and carry no evidential weight for a buyer; an external test is the planned next step
- No SIEM and no anomaly detection — monitoring yes, real-time security analytics no
If one of these gaps is decisive for your procurement, tell us — we answer with the status, not with a promise.
How we work on security
Four rules that apply to every change — small ones too.
- Class, not line: a fixed bug is searched as a class across the whole code and made impossible
- Every rule has a guard: type system, test or build gate — a rule without a guard is a wish
- Prove, do not claim: every security statement has a reference or an executed test
- No content in logs, reports or tickets — not even on error
Security questionnaire?
We answer your questionnaire with the status shown here — and send the DPA, subprocessor list and deletion concept on request.
Submit a questionnaireReady to bring your AI infrastructure to Europe?
Up and running in minutes — pick a tier, cancel monthly.
We are launching soon — secure one of the first spots.