# Security

> Encryption at rest, per-workspace isolation, OAuth sign-in instead of shared passwords, injection screening and instant revocation.

Canonical page: https://www.greatarrow.ai/security
Site map for agents: https://www.greatarrow.ai/llms.txt (full text: https://www.greatarrow.ai/llms-full.txt)

## Unreadable on disk and in backups

Your memories and the keys to your connected tools are encrypted before they are stored. Nobody browsing a disk or a backup can read them. Enterprise workspaces can add their own encryption key on top.

- AES-256-GCM at the application layer for stored content and integration credentials.
- Bring-your-own-key encryption on the Enterprise plan.

## One workspace can't see another

Every workspace is walled off from every other. Another customer's AI can never read your data — every request is bound to your workspace before it reaches storage.

- Tenant isolation is enforced in the application layer: every workspace-scoped query resolves its tenancy server-side, gated in CI.
- Postgres row-level security is enabled on every table as defence in depth.

## Apps never get your passwords

Your AI apps connect by signing in with your account, the same way you approve any app on your phone. Each app's access key is stored as a one-way fingerprint, shown to you once, and you can revoke it whenever you want — effective immediately.

- Standards-based OAuth 2.1 with PKCE and dynamic client registration for web AI clients.
- API access keys stored as SHA-256 hashes; revocable per client.

## Hidden instructions caught

Everything synced from your documents and connected tools is checked for hidden instructions before it can enter your AI's memory — so a malicious message can't steer your assistant.

- Prompt-injection screening runs on all integration-synced content at ingest.

## Keys and secrets aren't kept

Paste an API key or another secret by accident and it is replaced with a [redacted] marker before anything is saved.

- Recognised credential formats are detected at ingest and replaced with [redacted:credential]; the rest of the item is kept.

## AI asks before it acts

Meetings, campaigns and plans show you a preview first, and nothing goes out until you approve it. Sensitive data stays unshared unless you turn it on.

- Meeting invites are previewed before they are created; sensitive sharing categories are off in the default sharing policy.

## Your account

- Two-step sign-in is required for admins, and for the owners and admins of any workspace shared with other people.
- Everyone else turns on two-step sign-in within 7 days, or before connecting their first integration — whichever comes first.
- Sessions end after 7 days without use, and 30 days after sign-in at the latest.
- Every sign-in, sign-out and failed sign-in is recorded in an audit log; IP addresses are kept only as one-way hashes.

## Your control

- Every app with access is listed; revoke any of them in one click.
- Conversations from web AI apps are saved only when you ask.
- Export everything you have stored, or delete your account and its data.
- Share one project workspace with a client; your other workspaces stay yours.

## For IT and security teams

- **Scoped access** — Five permission scopes for AI apps: read, write, agents, integrations and admin.
- **Audit log** — Workspace actions are recorded, and every AI tool call is logged with its cost.
- **Sessions** — Session cookies the browser's scripts can't read, and passkey sign-in for every account.
- **Enterprise** — Your own encryption key, multi-seat workspaces and team roles.

The long version — what is stored, for how long, and your rights over it: https://www.greatarrow.ai/legal/privacy. Questions: https://www.greatarrow.ai/support.
