Preparing your workspace…
Preparing your workspace…
Security & privacy
Encrypted before it’s stored, walled off per workspace, screened before your AI reads it, and every app’s access revocable in one click.
How we protect it
Your memories and the keys to your connected tools are encrypted before they are stored. Nobody browsing a disk or a backup can read them. Enterprise workspaces can add their own encryption key on top.
AES-256-GCM at the application layer for stored content and integration credentials.
Bring-your-own-key encryption on the Enterprise plan.
Every workspace is walled off from every other. Another customer's AI can never read your data — every request is bound to your workspace before it reaches storage.
Tenant isolation is enforced in the application layer: every workspace-scoped query resolves its tenancy server-side, gated in CI.
Postgres row-level security is enabled on every table as defence in depth.
Your AI apps connect by signing in with your account, the same way you approve any app on your phone. Each app's access key is stored as a one-way fingerprint, shown to you once, and you can revoke it whenever you want — effective immediately.
Standards-based OAuth 2.1 with PKCE and dynamic client registration for web AI clients.
API access keys stored as SHA-256 hashes; revocable per client.
Everything synced from your documents and connected tools is checked for hidden instructions before it can enter your AI's memory — so a malicious message can't steer your assistant.
Prompt-injection screening runs on all integration-synced content at ingest.
Paste an API key or another secret by accident and it is replaced with a [redacted] marker before anything is saved.
Recognised credential formats are detected at ingest and replaced with [redacted:credential]; the rest of the item is kept.
Meetings, campaigns and plans show you a preview first, and nothing goes out until you approve it. Sensitive data stays unshared unless you turn it on.
Meeting invites are previewed before they are created; sensitive sharing categories are off in the default sharing policy.
Your account
Your control
Content is used to improve our models only while you have switched on “Improve our models” — and even then, only content you wrote yourself. Anything synced from your connected tools is never used for training, whatever you choose.
Google data is used only to provide the features you turn on, under Google’s Limited Use rules.
For IT and security teams
Five permission scopes for AI apps: read, write, agents, integrations and admin.
Workspace actions are recorded, and every AI tool call is logged with its cost.
Session cookies the browser's scripts can't read, and passkey sign-in for every account.
Your own encryption key, multi-seat workspaces and team roles.
Talk to usTry it on your own data