Security & governance

Your data never leaves the building

Designed for regulated finance environments — air-gapped, auditable, and governed by strict role-based access control.

JWT authentication

Stateless token auth with short-lived sessions.

RBAC enforcement

Role checks at every API boundary and route.

Secure file isolation

Per-workspace storage isolation, no cross-tenant access.

Audit logging

Immutable trail of every privileged action.

HTTPS support

TLS termination via nginx, HSTS-ready.

Configurable CORS

Strict origin allow-lists per environment.

Air-gapped capable

No mandatory outbound connections at runtime.

SSO-ready

SAML / OIDC on the roadmap for enterprise identity.

Role permissions

CapabilityUserAdminSuper Admin
Upload & RAG chat
Manage own workspace
Manage users & workspaces
Realtime audit trail
Runtime & engine config
Feature flags