Security

Enterprise-grade by construction

Security is not a bolt-on. The same controls that make the answers trustworthy make the platform safe to put your proprietary knowledge into.

The controls

What is audited, isolated, and never shared

SOC 2 Type II

Independently audited, continuously monitored

Our security controls are audited by an independent firm and monitored continuously. The report is available to customers and serious evaluators under NDA through the Trust Center.

GDPR

Compliant, with a controller and processor role for each case

Where we process personal information for our own purposes we are the controller; where customers deploy our agents, we process on their instructions. Data subject rights, retention, and transfers are covered in the privacy policy.

Tenant isolation

Your data is yours, and stays in your tenant

Documentation and product data live in an isolated tenant, encrypted in transit and at rest. Nothing is pooled with another customer.

No shared training

Your content never trains a model anyone else touches

Customer content is used to answer your users, not to train shared foundation models.

Cited by default

Every answer links back to its source

Inline citations point at the document and page each claim came from, so any answer can be verified before it is acted on.

Scoped and controlled

The agent says only what you allow

Knowledge hubs are permissioned, answers are scoped to the sources you connect, and evaluation suites run on your documents before go-live and after every change.

How access works

Four doors, each with its own lock

The detailed guides live on the docs site; this is the shape of it.

Signing in to the dashboard and agents

Google and Microsoft sign-in, email and password, or single sign-on through your identity provider on the enterprise plan. Admin and member roles keep conversation access where it belongs.

Login and SSO guide →

The agent on your public site

Publishable API keys are bound to the domains you allow. Every request is attested with AppCheck and scored by invisible reCAPTCHA, so a cloned page or a bot cannot use your key.

Widget security guide →

Reading your documentation

Ingestion reaches your systems from four static IP addresses you can allowlist, authenticates with the credentials you configure, and signs every crawl request so you can verify it is us.

Ingestion IPs and crawler verification →

What we collect about people

Names, work emails, and contact or billing details you give us, plus standard technical logs. No sensitive personal information. Conversation content is processed to answer and improve, and retained per your contract.

Data privacy summary →

Want the SOC 2 report or a security review?