Approved sources only
Read-only connectors ingest from sources your administrators designate. Ingested content becomes a draft that a human must approve before anything is answerable.
Secret blocking
Passwords, private keys, API keys, tokens and credentialed connection strings are detected by deterministic, security-reviewable pattern detectors — not by a model — and the containing document is refused ingestion outright, with the block recorded.
Redaction before embedding
Subscriber numbers, IMSIs, emails, IP addresses, internal hostnames and account identifiers are masked before any text is chunked or embedded. The model never sees them.
Versioning and rollback
Knowledge ships as versioned packs. Activations are reversible: any update can roll back to the previous approved state, with the change recorded.
These are architecture and control descriptions, not audit results. Current assurance status — implemented, tested, planned — is summarised in the Security & Trust Centre, and deeper material is available through the security architecture pack.