Written for a reviewer, not a marketer.
Everything stated as fact on this page is implemented and tested today. Everything on the roadmap says so in the same sentence, in the same size type. If you are doing a vendor review, this page is meant to answer you without a call.
Filled dot: in place and tested. Hollow dot: on the roadmap, not yet achieved.
The riskiest thing we do is take screenshots of your product.
So this is the control set we treat as load-bearing.
Isolation enforced by the build, not by convention.
The failure mode we care most about is one tenant seeing another's data, or a customer-facing answer citing an internal runbook. Both are pipeline failures rather than review items.
AI safety here means tests, not a paragraph about our values.
Prompt injection and cross-audience leakage are the two attacks that matter for a grounded support agent. Both are in the pipeline as adversarial suites.
Egress is deny-by-default, because we crawl and call out on your behalf.
What we have, and what we do not have yet.
- GDPR-ready: DPA, published subprocessor list, DSR export and erasure tooling, documented retention
- Role-based access control with an exportable audit log
- Envelope-encrypted credentials; API keys and webhook secrets hashed at rest
- Adversarial AI and cross-tenant isolation suites running in CI
- SOC 2 Type I — in progress. We will publish the report when there is a report.
- HIPAA-readiness posture — available for Enterprise on request. Not "HIPAA compliant".
- EU data residency — available for Enterprise on request.
- A contractual uptime SLA — the figures below are internal objectives only.
If a procurement checklist needs one of these today, we will tell you it is not available rather than describing it as "in flight" and hoping.
Published for transparency. These are the numbers we hold ourselves to internally; they are not a contractual commitment, and we will not present them as one until they are backed by a signed agreement and a track record.
Found something? It reaches an engineer, not a queue.
Email the security address directly rather than using the contact form. We acknowledge within one business day, we will not threaten you, and we will credit you if you want the credit.
Disclosure details