Built with security and data isolation at the core
This page describes how the platform actually handles data today, and is explicit about which formal certifications and enterprise controls are still ahead of us rather than behind us.
Tenant isolation
Each business's data is separated from every other business
Every conversation, message and knowledge base entry belongs to exactly one company account. Access rules are enforced in the database itself rather than only in the application, so a request that is not tied to a signed-in member of that company does not return that company's rows. Staff and administrators of one business cannot see another business's conversations or content, regardless of how the request is made.
- Row-level access rules scope every record to the company that owns it
- Dashboard queries run as the signed-in user, not as a privileged shared account
- Public chat widget traffic can only reach the one business its widget key belongs to
Data handling
AI replies are grounded only in your own approved content
The AI agent answers from the knowledge base your team has added to your own account. It does not draw on another customer's content, and when your material does not cover a question it escalates to a human instead of composing an answer from general knowledge. Visitor conversations stay scoped to the business the widget belongs to and are visible only to that business's team in their inbox.
- Retrieval is restricted to your knowledge base, never a shared or cross-customer pool
- Low-confidence and unsupported questions escalate rather than get answered speculatively
- Conversation history is readable only by members of the business that received it
What's coming
Formal controls planned for the Enterprise plan
We do not hold SOC 2, ISO 27001 or any other compliance certification today, and we will not imply otherwise. The following controls are planned as part of the Enterprise offering, consistent with how Enterprise is described on the pricing page.
- SOC 2 — on the roadmap, not yet obtained
- SSO and SAML — planned for Enterprise
- Audit logs — planned for Enterprise
- Advanced security controls and custom data retention — planned for Enterprise
If your review needs something specific documented, ask before you commit — we would rather tell you what is not ready yet.
Security or compliance questions?
Talk to us directly about isolation, data handling, or what an Enterprise review would need.