TRUST — SECURITY

Boring security, on purpose.

No heroes, no surprises: identity from your directory, permissions that start at zero, isolation chosen by the deployment home, and a register that sees every ring — we saved all the excitement for the product, not the security.

Short Answer

Seamless Enterprise security rests on four design decisions: work-account sign-in over SSO and SCIM with no shared keys, least privilege by default so nothing opens without a named enablement, isolation by the deployment home you choose, and encryption in transit and at rest — implementation details shared under NDA during evaluation.

IDENTITYthe register — sees every ringisolation by deployment homeencryption, transit & restleast privilege by default

IDENTITY FIRST

No shared keys — the directory is the door.

Sign-in with the work account over SSO, provisioning over SCIM: whoever joins appears with their role, and whoever leaves loses everything the moment the relationship ends — no parallel accounts to forget, no keys traveling by email.

  • The work account itself. No standalone signup — identity comes from your directory and answers to it.
  • Provisioning is automatic. SCIM opens and closes with joining and leaving — no manually tended lists.
  • Permission before access. Checked on every request, not discovered afterward in a report.
Access matrix — role vs. capability
ROLESOURCESSENSITIVE ACTIONSTHE REGISTER
Employee enabled for the role named approval own page only
Security admin no content — controls only with an entry about it events & metadata
Guest auditor scoped read-only

THE POSTURE

Least privilege, and isolation your home chooses.

The default state is zero: no source, capability, or internal assistant works before a named enablement. And isolation is not one promise but three homes — a trusted cloud with per-tenant isolation, your private cloud, or on-premises where the walls are yours.

  • Encryption is a design statement. In transit and at rest — details (algorithms, key management) under NDA during evaluation.
  • Isolation by home. Each deployment home draws its surface: what reaches the network, who operates, where data stands.
  • The sensitive needs a human. Named approvers recorded with the request — and the register sees every ring.
Our philosophy is that good security makes a poor dinner story: old, proven decisions applied without heroic exceptions — boring, here, is praise we accept gladly.

Implementation details are shared under NDA during evaluation — the same stance published on the technology page.

Review scope opened

A guest-auditor role, read-only, bounded by a named window and sections.

Access policies read

Reading the controls changes nothing — and the read itself is an entry.

Out-of-scope attempt stopped

A request for conversation content beyond the role — the gate stopped it and wrote the reason.

Sample export granted

A named administrator’s approval for a machine-shaped sample — the entry names who granted and who received.

THE TRAIL

A security-review request — as the register writes it.

This is what an external security team’s request looks like through the gate: a scope opened, boundaries honored, one attempt past the line stopped with its reason written — illustrative entries in the real entry’s shape.

For the security team: review us the way you review yourselves

A technical session with someone who builds the product: the security posture on the table, hard questions first — and what needs an NDA, we open with one.

SECURITY QUESTIONS

From real security reviews.

Do you share penetration-test results?

Shared under NDA during evaluation — we don’t publish them, and we claim nothing here beyond what we hand over there.

How does isolation between organizations work?

In the trusted cloud, per-tenant isolation at the data and runtime levels; whoever wants thicker walls chooses the private cloud or on-premises — isolation here is a choice of home before it is a technical promise.

Who are your sub-processors?

The list is shared during evaluation with the rest of the documents — we won’t hint here at what isn’t published, and on-premises the question itself narrows to what runs inside your walls.

What happens when an employee leaves?

Access follows the directory and ends with the relationship via SCIM — and their past usage stays in the register, because evidence does not leave with its authors.

Bring your hardest questions.

The best security reviews start skeptical — we welcome that, and we answer with what can be inspected, not what must be believed.