Skip to content

Security

Know how your work is protected.

Access controls, private document handling, evidence checks, and human approval are built into the product. Here is what those controls do—and what still needs to be verified for a pilot.

From access to release.

A customer workspace is called a House. Its access boundary follows the signed-in account through the database and private storage. A human operator must approve the work before a customer can read the memo.

  1. 01

    Signed-in customer

    Access starts with the customer account.

  2. 02

    Private document room

    Account-scoped database and storage rules apply.

  3. 03

    Evidence checks

    Unsupported material conclusions are withheld.

  4. 04

    Human release

    No customer-visible memo without approval.

Read the limits with the controls.

Local isolation tests are not proof of hosted isolation. The pilot deployment must separately verify access, multi-factor authentication (MFA) for operators, provider privacy, and retention. This page is not a certification, an audit opinion, or a guarantee of perfect security.

01

Customer-scoped access

Customer records and storage paths carry a House scope. Customer requests derive that scope from the signed-in session, not a route parameter. Row and storage policies are tested locally; the separate hosted two-House proof remains a release gate, so we do not call the boundary production-proven yet.

02

Private source handling

The pilot accepts PDF, Word, and Excel files in private storage. The server validates files before extraction, records source hashes and coordinates, and gives the browser short-lived links when a source must be opened.

03

Limits on model use

External model calls are scoped to a House and engagement, rate-limited, capped, and disabled when required provider-privacy evidence is missing. This is a control boundary, not a blanket zero-retention claim about every provider.

04

Citations and withholding

A material finding must resolve to an uploaded source excerpt. If the available room does not support the conclusion, the product withholds it instead of presenting it as fact.

05

Human approval and release

A completed model run creates work for a human operator to review. It does not create a customer-visible memorandum. Release requires an approved customer-visible version, and requesting changes retracts it. Cross-House review access is reserved for the configured operator allowlist and requires the deployment's MFA gate before customer use.

06

Audit and retention

The product records security- and workflow-relevant events without putting raw document text in analytics or status fields. Source records support expiry, but a pilot must not begin until the agreed retention period, deployment default, and scheduled deletion sweep have a verified operational receipt.

Procurement and review

Bring the questions your review requires.

We will answer against current evidence and identify controls that are still release gates. We will not substitute roadmap language for a certificate or completed test.

Start a security review →Read the principles →