SECURITY & GOVERNANCE
Know your context.
Understand the controls.
SOC 2 Type II in progress.
Our SOC 2 Type II is in progress. Contact the team to discuss your review requirements and the current status.
Understand what enters.
See how it is used.
A conceptual view of the platform. The exact data captured depends on the connected source, agent and workflow.
01
Connected work
Supported agent sessions and connected tools provide the working context.
02
Retained knowledge
Brains organize saved memories and material around an area of work.
03
Context in action
People and agents retrieve relevant knowledge; scoped rules guide supported workflows.
Controls around the way your team works.
Understand who can access shared context, how sources connect, and where rules apply.
01
Brain access
Brains include per-person read, edit, and admin access. Sharing a Brain and connecting an external source are separate actions.
02
Connection scope
Review shared team connections separately from private accounts. Confirm the requested access and supported data for each source in your evaluation.
03
Scoped Rulebooks
Rules apply through their Rulebook’s scope, which can bind selected people or an organization. Review the rule and trigger together before enabling it for a workflow.
04
Inspectable activity
Sessions and Rulebook fire history help you inspect recorded agent work and rule delivery. Reporting scope and available measurements depend on the session and view.
Make the data review
specific to your environment.
Agree on the deployment and data boundaries for the workflow you plan to connect. The review should cover:
Capture and processing
Session transcripts, tool calls, connected-source content and derived memories; which providers process them and what can be excluded.
Hosting and access
Storage and processing locations, deployment options, identity requirements and access boundaries.
Retention and exit
Retention by data class, deletion and backup handling, exports, disconnection and offboarding.
Model use and documentation
Model-provider processing and training terms, subprocessors and the documentation needed for your evaluation.
Deployment, retention and model-processing details are confirmed with the team for your evaluation.
Bring your requirements.
Get a focused review.
Start with your intended workflow, the data it touches and your security requirements. We can use those to scope the discussion.