Defense-in-depth across identity, data, and the AI supply chain.
Per-user keypairs; private keys wrapped by password-derived KEK, unwrapped only in memory.
TLS 1.3 in transit. AES-GCM at rest. Optional customer-managed keys on Enterprise.
Append-only ledger. Public Merkle roots. Third-party verifier endpoint.
Per-workspace RLS. Region pinning. Optional dedicated compute.