Security
Confidentiality you can verify, not just read in a contract.
Every control below is architectural. It holds because of where the system runs and how access is enforced — not because of a promise in a document.
Private infrastructure
Inference, retrieval and storage run in infrastructure dedicated to your institution — on campus or in a private tenancy. No shared multi-tenant model.
Institution ownership
Your documents, index and embeddings belong to the institution. Exportable in an open format, at any time, without negotiation.
Encrypted storage and transport
Data is encrypted at rest and in transit. Keys are scoped to the institution's deployment.
Role-based access control
Chairman, principal, dean, HoD, faculty and student roles each carry an explicit permission set. Access is denied by default.
Audit logs
Every query, retrieval and agent action is logged with user, role, timestamp and source documents — reviewable by management and IT.
Zero training on customer data
Institutional documents and conversations are never used to train shared models. Your material improves only your deployment.
Document isolation
Confidential documents carry their own access scope. A helpful answer can never surface a document the user may not read.
Department isolation
Departments are separated inside the knowledge base. Retrieval respects that boundary on every request.
Your IT team will have harder questions. Send them to us.
We are happy to walk a CIO or system administrator through the deployment architecture in technical detail.