Zero-trust by design.
Fingerprint by default.
Every artifact SHA-256 fingerprinted. Every action hash-chained into an immutable, workspace-isolated audit ledger. Private-by-default, GDPR- and CCPA-aligned.
Ten load-bearing security guarantees.
Encryption at rest
AES-256 across every document, artifact, and metadata record. Per-user keys.
Encryption in transit
TLS 1.3 end-to-end, HSTS enforced, certificate pinning on managed clients.
SHA-256 hash-chained audit
Every action fingerprinted, sealed into an immutable ledger with tamper triggers.
Sign-in & MFA
Google, Apple, GitHub, email — plus TOTP, passkeys, and hardware keys.
Personal BYO-LLM vault
Encrypted, per-user provider keys. Rotate any time. Never shared.
Workspace isolation
Strict data, storage, audit, and AI-configuration isolation between workspaces.
Malware scanning
Every upload scanned. Sandboxed conversion pipeline. No filetype trust by default.
Rate limiting & DDoS
Adaptive rate limits, IP allowlists, and edge DDoS mitigation.
PII redaction
Deterministic redaction of names, IDs, and structured PII with legal-grade opacity.
Data residency
Storage and processing pinned to a region. EU or US.
Aligned with the privacy standards that protect you.
Export, delete, and rectify your data any time
Your consumer privacy rights, honored
Modern web security best-practices across the stack
Every action hash-chained and signed
Prompts never leave your workspace
No behavioural tracking on your documents
Private by default. Yours by design.
Delete a file and the fingerprint remains — proof of what happened, without keeping the file.