Skip to content
Security

Zero-trust by design.
Fingerprint by default.

Every artifact SHA-256 fingerprinted. Every action hash-chained into an immutable, workspace-isolated audit ledger. Private-by-default, GDPR- and CCPA-aligned.

Controls

Ten load-bearing security guarantees.

Crypto

Encryption at rest

AES-256 across every document, artifact, and metadata record. Per-user keys.

Crypto

Encryption in transit

TLS 1.3 end-to-end, HSTS enforced, certificate pinning on managed clients.

Audit

SHA-256 hash-chained audit

Every action fingerprinted, sealed into an immutable ledger with tamper triggers.

Access

Sign-in & MFA

Google, Apple, GitHub, email — plus TOTP, passkeys, and hardware keys.

Access

Personal BYO-LLM vault

Encrypted, per-user provider keys. Rotate any time. Never shared.

Isolation

Workspace isolation

Strict data, storage, audit, and AI-configuration isolation between workspaces.

Runtime

Malware scanning

Every upload scanned. Sandboxed conversion pipeline. No filetype trust by default.

Runtime

Rate limiting & DDoS

Adaptive rate limits, IP allowlists, and edge DDoS mitigation.

Privacy

PII redaction

Deterministic redaction of names, IDs, and structured PII with legal-grade opacity.

Residency

Data residency

Storage and processing pinned to a region. EU or US.

Privacy

Aligned with the privacy standards that protect you.

GDPR-aligned

Export, delete, and rectify your data any time

CCPA-aligned

Your consumer privacy rights, honored

OWASP-hardened

Modern web security best-practices across the stack

SHA-256 ledger

Every action hash-chained and signed

BYO-LLM

Prompts never leave your workspace

Zero telemetry

No behavioural tracking on your documents

Private by default. Yours by design.

Delete a file and the fingerprint remains — proof of what happened, without keeping the file.