Contact us

Trust Center · Security Architecture

Security Architecture

For CTOs, CISOs, and security reviewers. Architecture, isolation, controls, and subprocessors, stated precisely.

Architecture, in one paragraph

Tenant-isolated workspaces in Canadian-region infrastructure. Permission enforcement happens before retrieval, not after generation, the model never sees what the viewer isn't allowed to see. Open-source-first stack, model-neutral, self-hostable for enterprise deployments.

  • Tenant isolation: dedicated schema per workspace, enforced at the data layer
  • Encryption: TLS 1.3 in transit, AES-256 at rest
  • Permission-preserving retrieval: access checks precede any model context
  • Connector scopes: read-only, minimum necessary, listed per connector below

Connector scopes, exact

What we request per connector, in full, so your security team can approve without a call:

  • Identity / SSO: read users, read groups, read OAuth grants, nothing else
  • Email & calendar metadata (optional): headers and attendee graphs only, never bodies
  • Document stores (optional): read-only, scoped to folders you select
  • DNS & certificates: public sources only, no credentials required at all

Certification status, against the real timeline

SOC 2 Type I readiness work is underway now; Type II observation window begins after the first design-partner deployments, with the date published here when it starts. An independent penetration test is scheduled ahead of general availability. We will update this page the week anything changes, the discipline this site sells applies to itself.

Responsible disclosure & status

Security reports go to [email protected] and are acknowledged within 48 hours. Subprocessors with regions are listed on the legal page. A public status page launches with general availability.

A question this page didn't answer?

Security reports: [email protected] · Employee concerns: [email protected] · Everything else: [email protected]