Security

Defense-in-depth across identity, data, and the AI supply chain.

Ed25519 identities

Per-user keypairs; private keys wrapped by password-derived KEK, unwrapped only in memory.

Encryption

TLS 1.3 in transit. AES-GCM at rest. Optional customer-managed keys on Enterprise.

Auditability

Append-only ledger. Public Merkle roots. Third-party verifier endpoint.

Isolation

Per-workspace RLS. Region pinning. Optional dedicated compute.