Security and governance

Where the context comes from, what is kept, and what you control

Written to be checked rather than believed. If a line here is wrong, it is a defect and we will correct the page.

LAST REVIEWED 01 SEP 2026

Where context comes from

The model reads a set you assemble. There is no background crawl of the tenant and no open web access.

ItemHow it works
SourcesRecords you connect or upload: documents, workbooks, and prior filed artifacts inside your tenant.
AssemblyA person or a saved scope selects the records for each generation. The selection is written to the manifest.
Open webOff. A source outside the tenant has to be added by a named person, and it appears in the manifest as external.
Other tenantsNever. Each tenant is a separate database, so there is no query that could reach another customer's records.
TrainingYour content is not used to train models.
Model providerAnthropic, through a single gateway. The provider used is recorded per artifact.

What is retained

The governance record is the part we keep on purpose.

ItemHow it works
Filed artifactsKept for the life of the tenant, then exported and deleted on request. These are your records.
Context manifestsKept with the artifact they belong to. Deleting the artifact deletes the manifest.
Audit logWho read, generated, signed, and exported. Append only, written in the same transaction as the change it records.
Specific windowsStated in your contract rather than on this page, because they are set per tenant and we will not publish a number we would then have to qualify.

What a tenant controls

These are settings, not requests to us. An administrator changes them and the change is logged.

ItemHow it works
Who may signPer document type. Sign-off roles are named people and cannot be groups or service accounts.
Source scopesWhich records are available as context, by folder, workspace, or record type.
Export gateWhether unsigned drafts may be downloaded at all. Off by default.
RegionCanadian region. Data does not leave it without a written change.
Access reviewsA standing list of every account with a sign-off role.
Posture

The infrastructure, plainly

HostingGoogle Cloud, northamerica-northeast2 (Toronto).
EncryptionTLS in transit, encrypted at rest.
TenancyA separate database per tenant, not a shared table with a customer column. Isolation is structural rather than a query filter that could be forgotten.
AuthenticationSSO through Google Workspace or Microsoft Entra ID.
Sign-off identityA signature is bound to an authenticated session and a named account.
Sub-processorsGoogle Cloud and Anthropic. Listed with purpose in the contract.
Status

What we have not done yet

A page like this usually lists certifications. Ours does not, because we do not have them.

  1. N01No SOC 2 reportThere is nothing to send you today, and we will not name a date we have not committed to.
  2. N02No ISO 27001Not started. We will say so until it is.
  3. N03No penetration test report to shareThe summary will be available to customers when one exists.
  4. N04Not yet incorporatedOwned AI Inc. is in formation. Contracts today are signed by the founding principal in their own name.

If your approval process requires a SOC 2 report, we are not a fit yet, and we would rather tell you on this page than in month three.

For a reviewer

Ten minutes to check us

If you are the person on the hook for approving this, these are the questions that actually separate vendors.

Ask us for
C01A live artifact with its manifest, generated on your own document during the call.C02The audit log entry for that generation, exported.C03The tenant settings screen, showing who may sign and what may be exported.C04The sub-processor list and the model provider terms.
Do not accept from anyone
X01A trust page with badges and no report behind them.X02A claim that a model does not retain data, without the provider term that says so.X03An audit trail that records the tool and not the person.X04A sign-off that a service account can perform.

Send this page to whoever has to approve it

We will answer a security questionnaire, and we will mark the questions we fail rather than leaving them blank.