3
AC
Platform/Security

Data Privacy & Security

Encryption, secrets, scanning, audit, DR — plus privacy controls for PII, redaction, residency and policy-gated evaluators.

Security controls

21

Privacy features

16

CMK / secrets

Enabled

Architecture security controls

Built into platform design

Encryption in transit (TLS 1.3)Encryption at restTenant-specific encryption optionsCustomer-managed keys (CMK)Secrets managementKey rotationSecure credential storageWAFDDoS protectionRate limitingInput validationMalware scanningDependency scanningContainer scanningAudit loggingImmutable security logsSIEM exportVulnerability managementBackupDisaster recoveryBusiness continuity

Privacy features

Tenant-configurable

PII discoveryAutomatic transcript redactionAudio redaction / tone replacementPhone-number maskingSelective recordingRetention policiesRight-to-delete workflowLegal holdData exportData-residency selectionConsent metadataPurpose limitationConfigurable storage of raw prompts/responsesNo external evaluator without policy permitPrivate model endpointsCustomer-hosted evaluators

Evaluator & model policy

Sensitive LLM inputs and transcripts are not sent to external evaluator models unless permitted by the tenant’s policy.

Private model endpoints and customer-hosted evaluators are supported for air-gapped or residency-constrained deployments.

Secrets are stored in a secrets manager; UI shows only masked prefixes. Key rotation and customer-managed keys are available at organization level.