Enterprise identity
Provider-neutral OIDC with a Microsoft Entra profile. Users authenticate against your tenant; there are no separate vendor accounts.
RBAC enforced in-query
Role-based access control is applied inside retrieval queries, not as an interface veneer. A user without rights to a knowledge pack cannot surface its content through any prompt.
ACL preservation
Source-system access controls map to knowledge-pack permissions during ingestion, fail-closed: if a mapping is uncertain, access is denied until reviewed.
Administrative and support access
Support access is off by default. When help is needed, a session is granted explicitly and is time-limited, role-scoped, revocable and fully audited.
These are architecture and control descriptions, not audit results. Current assurance status — implemented, tested, planned — is summarised in the Security & Trust Centre, and deeper material is available through the security architecture pack.