Email, documents, code, decisions — this platform only works if you can trust it with all of it. Here is exactly how it is protected, in plain language.
Your memories and the credentials for your connected tools are encrypted before they are stored. Nobody browsing a disk or a backup can read them.
AES-256-GCM at the application layer for stored content and integration credentials.
Every workspace is isolated at the database layer. Another customer's AI can never read your data — the database itself refuses.
Postgres row-level security on every workspace-scoped table, enforced below the application.
Your AI apps connect by signing in with your account, the same way you approve any app on your phone. We never ask you to hand one tool your password for another.
Standards-based OAuth 2.1 with PKCE and dynamic client registration for web AI clients.
Every connected app's access key is stored as a one-way fingerprint and shown to you exactly once. Revoke any of them from your account whenever you want — effective immediately.
API access keys stored as SHA-256 hashes; revocable per client.
Everything synced from your email, documents, and tools is checked for hidden instructions before it can enter your AI's memory — so a malicious message can't steer your assistant.
Prompt-injection screening runs on all integration-synced content at ingest.
Enterprise workspaces can supply their own encryption key on top of everything above.
Bring-your-own-key encryption on the Enterprise plan.
The long version — what we store, for how long, and your rights over it — lives in the privacy policy. Questions a page can’t answer? Ask us directly.
Start free