Secure by
architecture.
Not by promise.

Your teams get AI colleagues that amplify their work. Your security team gets something rarer: agents that can never see more than the person asking — enforced by deterministic controls that sit outside the model, on infrastructure that is yours alone.

Identity-based access

Agents always act as the user — never as a shared super-account.

Deterministic guardrails

Access rules enforced outside the AI. Same result, every time.

PII & GDPR masking

Personal and regulated data masked before storage or display.

Per-customer isolation

Dedicated agents, compute, and storage. Region of your choice.

Security Architecture

How data moves.
And where it stops.

Every request flows through four layers. The AI operates in the middle two — but the decisions about what it may see are made above and below it, by controls it cannot bypass.

01

Identity & Access

One governed identity per person

Access starts with who you are — not what you ask.

Onboarded where work happens

When someone joins a project channel in Slack, a secure auth persona is created for them and access is assigned based on their role on that project.

One auth persona per person

Each person gets a single governed identity that carries their exact permissions into every request. Agents always act as the user — never as a shared super-account.

User-to-machine tool auth

Notion, Jira, and other connected tools authorize with each person's own account. Tools only ever see what that person can see.

↓  agent requests data on the user's behalf
02

AI Agents

Capable, but never in charge of access

Agents answer questions, draft work, and keep projects moving. They request information on the user's behalf — but they never decide what data they're allowed to see. That decision is made below them, by controls they cannot bypass.

AStrategy SResearch PDesign FEngineering PData & Marketing
↓  every request passes the checkpoint
03

Independent Security Layers

Deterministic — not model judgment

These run outside the AI. They are deterministic rules, so they apply the same way every time — even if an agent tries to reach beyond what a user is allowed to access. The agent physically cannot see what these layers remove.

Deterministic · Independent of the agent

Access filter

Company memory is tagged with the channel each piece of information came from. Before any result reaches an agent, this layer checks the asking user's channel access and removes everything they aren't a member of.

Result: a user only ever retrieves data from channels they belong to.
GDPR & PII detection

Data masking & anonymization

A separate pass scans content for personal and regulated data — names, emails, phone numbers, IDs, and other PII — and masks or anonymizes it before it is stored or shown. This holds even when the underlying source contains sensitive details.

Result: regulated data stays protected by default, not by trust.
↓  only permitted, protected data passes
04

Customer Isolation

No shared data path — ever

Every customer is fully separated. Agents, compute, and storage are hosted independently — down to the region. There is no shared data path between customers, so one customer's information can never reach another's.

Customer A

Dedicated · Isolated
Dedicated agentsHosted only for this customer
Separate compute (VMs)No shared processing
Isolated storageOwn encrypted data store
Region: chosen per customerIncluding EU and Australian regions

Customer B

Dedicated · Isolated
Dedicated agentsHosted only for this customer
Separate compute (VMs)No shared processing
Isolated storageOwn encrypted data store
Region: chosen per customerIncluding EU and Australian regions
···

Customer N

Same model, fully separate

Each new customer gets the same isolated environment.

Deployment

Your model.
Your region. Your rules.

The system deploys into your world — not the other way around.

Inference

Runs on your own LLM

Agents run inference on your enterprise LLM API — no customer data leaves your existing model environment or your existing agreements with your model provider.

Residency

Any region you nominate

Deployment is available in any customer-nominated cloud region, keeping data residency aligned with your regulatory and sovereignty requirements.

Control

Caps you define

Usage and inference limits are set by you, so spend and consumption stay predictable and within the boundaries your organization approves.

Governance

Built for your
security review.

Enterprise procurement shouldn't take six weeks of email ping-pong. Everything your legal, privacy, and security teams need is packaged and ready.

Enterprise agreement package

A complete MSA with dedicated schedules for data processing (DPA), data sovereignty, and service levels — structured for review by your counsel from day one.

GDPR-aligned by design

PII detection, masking, and anonymization are built into the data path itself — not bolted on. Personal data is protected before it is ever stored or displayed.

Least-privilege everywhere

Permissions mirror your existing channel and tool access. No new access model to govern, no standing super-user credentials to audit.

Pilot-first engagement

Start with a scoped, fixed-fee pilot across one or two squads. Prove value inside your own environment before any broader commitment.

For Security Reviewers

The questions your
CISO will ask.

Does our data train your models?
No. Inference runs on your own enterprise LLM API, under your existing agreements with your model provider. Your data never leaves your model environment and is never used to train anything outside it.
Can an agent access data a user can't?
No. Agents act only as the requesting user, and a deterministic access filter — running outside the model — removes anything from channels the user doesn't belong to before the agent ever sees it. This is a rule, not model judgment, so it applies identically every time.
How is PII handled?
A separate detection pass scans for names, emails, phone numbers, IDs, and other personal or regulated data, and masks or anonymizes it before storage or display — even when the underlying source contains sensitive details.
Is our environment shared with other customers?
No. Every customer runs on dedicated agents, separate compute, and isolated, encrypted storage in a region you choose. There is no shared data path between customers.
How do connected tools authenticate?
Through user-to-machine authentication: each person authorizes tools like Notion and Jira with their own account. Integrations only ever see what that individual can see — there are no shared service accounts with broad access.
Where can we deploy?
In any customer-nominated cloud region, aligned with your data residency and sovereignty requirements. Regional deployment, key management, and retention terms are covered in the data sovereignty schedule of the enterprise agreement.