Security & trust
The parts nobody enjoys building — key encryption, tenant isolation, retention, redaction — are the parts we obsess over, so you never have to.
Provider credentials live server-side, encrypted with KMS, and are never returned after you save them.
BYOK vault
Every query is scoped to your organization and site. Tenant A can never read Tenant B's data.
Multi-tenant
The public config the widget reads carries theme and launcher settings only — no secrets, ever.
Public surface
Keep transcripts, or run analytics-only. Set retention windows that match your policy.
Privacy
Strip sensitive details from stored conversations when your rules require it.
Redaction
Per-site limits and abuse detection keep cost and exposure under control.
Guardrails
Sensitive actions are recorded. In Phase 3, every tool call is logged end to end.
Accountability
Guidance for a tight Content-Security-Policy so the widget loads without loosening your site.
CSP
SSO, custom retention, private deployment options, and a security review for regulated teams.
Enterprise
The principle
Bring-your-own-key means exactly that. We encrypt your credentials, scope them to your site, test them before they go live, and never expose them — not to the browser, not back to you through any API.
For regulated and enterprise teams, we'll walk through isolation, retention, and provider data policy in detail.