Platform/Security
Data Privacy & Security
Encryption, secrets, scanning, audit, DR — plus privacy controls for PII, redaction, residency and policy-gated evaluators.
Security controls
21
Privacy features
16
CMK / secrets
Enabled
Architecture security controls
Built into platform design
Encryption in transit (TLS 1.3)Encryption at restTenant-specific encryption optionsCustomer-managed keys (CMK)Secrets managementKey rotationSecure credential storageWAFDDoS protectionRate limitingInput validationMalware scanningDependency scanningContainer scanningAudit loggingImmutable security logsSIEM exportVulnerability managementBackupDisaster recoveryBusiness continuity
Privacy features
Tenant-configurable
PII discoveryAutomatic transcript redactionAudio redaction / tone replacementPhone-number maskingSelective recordingRetention policiesRight-to-delete workflowLegal holdData exportData-residency selectionConsent metadataPurpose limitationConfigurable storage of raw prompts/responsesNo external evaluator without policy permitPrivate model endpointsCustomer-hosted evaluators
Evaluator & model policy
Sensitive LLM inputs and transcripts are not sent to external evaluator models unless permitted by the tenant’s policy.
Private model endpoints and customer-hosted evaluators are supported for air-gapped or residency-constrained deployments.
Secrets are stored in a secrets manager; UI shows only masked prefixes. Key rotation and customer-managed keys are available at organization level.