Security built for regulated operations
Controls and certifications vary by deployment and contract. Your order form, DPA, and security packet remain the source of truth—this page is a plain-language overview.
Access and authentication
Access is gated by your identity provider and role assignments. Data is scoped to your organization so people only see what they are permitted to see.
Data in transit and at rest
Traffic uses modern TLS. Stored artifacts and metadata live in infrastructure configured for reliability and encryption appropriate to the deployment model you choose.
AI processing
Model-assisted analysis runs in our controlled pipeline—not as ad-hoc prompts in a consumer chat product. Retention and subprocessors follow your data processing terms.
Responsible disclosure
If you believe you have found a security issue, reach us through the contact form with enough detail to reproduce. We take reports seriously and coordinate disclosure with customers when needed.

