Job · Satisfy the review

Screenshots of your admin console cannot leave with customer data in them.

The objection that stops a capture tool at the security review is not a feature gap — it is that the tool takes pictures of production. Cairn was built around that objection rather than around it.

In their words

Three sentences from security reviewers.

“Your tool screenshots our production admin. Explain the redaction.”

What Cairn does:

Four tiers, with enforced policy redaction running at ingest — before any human sees the image. Strict originals mode encrypts the original, never serves it, and deletes it once a derivative exists.

“What stops the internal runbook appearing in a customer-facing answer?”

What Cairn does:

Enforcement at retrieval rather than in the UI, plus cross-audience leak probes in CI with a nightly scan. A leak is a build failure, not an incident.

“Are you SOC 2?”

What Cairn does:

Not yet. Type I is in progress and we will publish the report when there is a report. We would rather lose the deal than describe it as done.

First thirty days

A pilot that a reviewer can actually approve.

Not a migration project. Each week produces something usable on its own, so you can stop at any point and still be ahead.

  1. Step 1Read the security page firstWritten for a reviewer, not a marketer. Tenancy, redaction, AI safety, egress, and an explicit list of what is still roadmap.
  2. Step 2Set policy before captureEnforced redaction rules and strict originals configured up front, so the first screenshot taken is already governed.
  3. Step 3SSO, SCIM, rolesSAML and SCIM provisioning, owner/admin/agent roles, and an exportable audit log wired before the pilot opens up.
  4. Step 4Pilot one internal audienceStart internal-only. Public publishing stays behind an approval policy until you are ready to turn it on.
What you actually use

Governance, redaction, and audit

The rest of the product is there when you need it. These are the parts this job leans on.

Security →

The full control set: capture and redaction, tenancy enforced by the build, AI safety suites, deny-by-default egress, and the compliance split.

Capture →

Masked at the source — field labels recorded, values never. An architectural rule with tests, not a toggle.

Knowledge →

Per-audience governance with a content × audience matrix, custom audiences, and approval policy for public publishing.

AI agent →

Grounding policy, regression-tested refusal, permissioned tool calls, and a fenced execution model for "do it for me".

Developers →

Contract-first API, signed webhooks, MCP server, and the audience scopes enforced identically across all of them.

Where Cairn is the wrong choice

Three answers a procurement checklist will not like.

  • SOC 2 Type I is in progress and not achieved. If your policy requires a completed report today, we do not clear it.
  • HIPAA-readiness posture and EU data residency are Enterprise-on-request, not standing capabilities. Ask and we will tell you exactly what exists.
  • There is no contractual uptime SLA yet. The published figures are internal service objectives and we will not dress them up as more than that.