Your user feedback is your asset, not our training data
Three deployment models, tightened as needed. From data residency to AI revocability, security boundaries are visible in the product — not buried in a contract appendix.
Three deployment models, choose by security level
| Model | Best for | Data & models |
|---|---|---|
| Shared SaaS | Teams that want it to just work | Data is stored in platform-managed clusters with logical isolation between tenants; models are dispatched by the platform. |
| Bring your own model key (BYOK) | Teams with requirements on the model call path | LLM calls run through your own model account—raw feedback never counts against platform quota. We handle orchestration only. |
| Self-hosted deployment | Highly regulated enterprises like finance and healthcare | The entire system runs inside your VPC / data center, so data never leaves your network. Supports integration with internal model gateways. |
Four-tier data privacy protection
Rolled out by sensitivity level, with progressive enablement available in the enterprise plan.
Masking & obfuscation
PII like phone numbers, emails, and order numbers in feedback is automatically detected and masked before storage.
Encryption & isolation
End-to-end encryption in transit and at rest, independent key management for credentials, and strict tenant data isolation.
You own the call chain
With BYOK / self-hosting, model calls and data storage stay within your control plane.
Confidential computing
Enterprise plan offers a confidential computing environment with runtime memory-level protection — even the operator can't peek.
Every AI step is visible, controllable, and reversible
Transparent
Every AI recommendation shows the source feedback, reasoning, confidence score, and action steps. Click in to see exactly why something's P0 or why it was assigned to a given person.
Controlled
Before acting, AI drafts a plan and passes through an authorization gate—execution only happens after confirmation. Outbound notifications and permission changes always require human approval. Every action is logged for audit and can be undone within a set window.
Channel credential security
OAuth first
For channels that support one-click authorization, you'll never need to paste a secret key. Scopes are kept to the minimum needed to read feedback.
Key custody
Channel credentials are encrypted and stored in a key management service; the UI never displays plaintext. Revoke access anytime with one click.
Outbound protection
Connector outbound requests are restricted by domain allowlist to prevent SSRF. Connector health and error details are visible in real time.
Tell us your security requirements
Compliance checklists, deployment assessments, self-hosted POCs — our Enterprise team will work with you directly.
Contact us