Security at User Evaluation

Security facts at the level we can support.

This page separates controls that are available in the product from certifications, evidence, and contractual commitments that must be confirmed for a specific procurement review.

Assurance status

No badge without current evidence.

Ask for the current scope, dates, and supporting documents before relying on any certification or regulatory status.

SOC 2

We do not represent a SOC 2 certification on this page. Request the current status, audit scope, and available evidence from security.

ISO 27001 and ISO 42001

We do not claim either certification here. Ask which governance documents and control mappings are currently available.

Privacy, GDPR, and DPA

The Privacy Policy describes data use and individual rights. DPA and controller/processor requirements are reviewed in the applicable contract.

HIPAA

Healthcare requirements are reviewed on request. This page does not claim HIPAA eligibility, PHI support, or availability of a BAA.

Implemented product controls

What an Enterprise workspace can enforce today.

Customer-data training policy

We do not use Customer Data to train models that we develop. Contracted AI providers process research content when required to deliver a requested feature. Their handling and retention terms are confirmed for the services in your security review.

Private research assets

The current upload path stores research assets privately and delivers them using expiring signed links instead of public object URLs. Legacy storage is reviewed during procurement where relevant.

SSO and provisioning

Enterprise organizations can configure SAML 2.0 or OpenID Connect and use SCIM 2.0 provisioning. The entitlement is checked by the server.

Audit and retention controls

Organization admins can inspect and export recorded security and governance events. Retention changes support a visible dry-run mode before enforcement.

Security review

The details we confirm in writing.

Architecture, encryption, hosting region, model providers, subprocessors, incident response, vulnerability management, and deletion timelines can change. We provide the current facts and available evidence during review instead of freezing them into unsupported marketing copy.

  • Current certification and audit status, including scope and dates
  • Hosting region and any contract-specific residency commitment
  • Current subprocessor and model-provider list
  • Available penetration-test or vulnerability-management evidence
  • Incident-response and data-deletion commitments in the contract

Data location is contract-specific.

Tell us the regions and data flows your policy permits. We will confirm the current deployment facts and state any residency commitment in writing; this page makes no blanket EU-hosting promise.

Talk to security.

Send the questionnaire and evidence list. We will identify which documents exist, their dates, and which requirements need contract language.