Security

Your user feedback is your asset, not our training data

Three deployment models, tightened as needed. From data residency to AI revocability, security boundaries are visible in the product — not buried in a contract appendix.

Three deployment models, choose by security level

ModelBest forData & models
Shared SaaSTeams that want it to just workData is stored in platform-managed clusters with logical isolation between tenants; models are dispatched by the platform.
Bring your own model key (BYOK)Teams with requirements on the model call pathLLM calls run through your own model account—raw feedback never counts against platform quota. We handle orchestration only.
Self-hosted deploymentHighly regulated enterprises like finance and healthcareThe entire system runs inside your VPC / data center, so data never leaves your network. Supports integration with internal model gateways.

Four-tier data privacy protection

Rolled out by sensitivity level, with progressive enablement available in the enterprise plan.

L1

Masking & obfuscation

PII like phone numbers, emails, and order numbers in feedback is automatically detected and masked before storage.

L2

Encryption & isolation

End-to-end encryption in transit and at rest, independent key management for credentials, and strict tenant data isolation.

L3

You own the call chain

With BYOK / self-hosting, model calls and data storage stay within your control plane.

L4

Confidential computing

Enterprise plan offers a confidential computing environment with runtime memory-level protection — even the operator can't peek.

Every AI step is visible, controllable, and reversible

Transparent

Every AI recommendation shows the source feedback, reasoning, confidence score, and action steps. Click in to see exactly why something's P0 or why it was assigned to a given person.

Controlled

Before acting, AI drafts a plan and passes through an authorization gate—execution only happens after confirmation. Outbound notifications and permission changes always require human approval. Every action is logged for audit and can be undone within a set window.

Channel credential security

OAuth first

For channels that support one-click authorization, you'll never need to paste a secret key. Scopes are kept to the minimum needed to read feedback.

Key custody

Channel credentials are encrypted and stored in a key management service; the UI never displays plaintext. Revoke access anytime with one click.

Outbound protection

Connector outbound requests are restricted by domain allowlist to prevent SSRF. Connector health and error details are visible in real time.

Tell us your security requirements

Compliance checklists, deployment assessments, self-hosted POCs — our Enterprise team will work with you directly.

Contact us