Security
Security you can trace
Postgres row-level security isolates tenant data at the database layer, roles scope what each member can reach, every answer is grounded in your own knowledge and cited, and we never train models on your content.
We recently began our SOC 2 Type II and GDPR compliance programs. Those certifications are not complete yet, and we will not claim otherwise. The practices below are in place today.
Tenant isolation by default
Every organization's data is separated at the database layer. Access is enforced with Postgres row-level security, so one tenant can never read another tenant's assistants, knowledge or conversations.
Role-based access control
Each member holds a role that scopes what they can see and change within their organization. Our managed authentication layer handles sign-in, with single sign-on through Google and Microsoft.
Encryption in transit and at rest
The platform serves every request over TLS, and our managed database and storage providers encrypt data at rest. Secrets and access tokens are stored sealed, never in plain text.
Your data is never used to train models
The content and conversations flowing through your assistants are used only to answer questions for your organization. We do not use them to train foundation models, and we do not share them with other customers.
Grounded, auditable answers
Assistants answer from the knowledge you connect and cite the exact Source behind each response, so you can trace any answer back to the page or document it came from rather than to an opaque model guess.
Secure integrations
Connections to knowledge sources, help desks and identity providers use scoped credentials that are sealed at rest. Operational alerts flag an integration whose credentials stop working, so someone can fix it before answers go stale.
Compliance
Compliance and governance
We are early in our formal compliance work, and deliberate about what we claim. Here is where things stand today.
- SOC 2 Type II
- Program recently started. We are defining and implementing the controls needed for an audit of security, availability and confidentiality. There is no report yet, and we will not imply otherwise.
- GDPR
- Compliance work underway. We honor data access and deletion requests today and use Standard Contractual Clauses for international transfers.
- Data processing
- When customers run their own assistants, Ciele acts as a processor and the customer is the controller of their conversation and end-user data.
- Subprocessors
- A short, published list of hosting, database, email and model providers processes data on our instructions. We update the subprocessor page whenever that list changes.
- Data residency
- The managed platform runs on European infrastructure. Organizations that need a specific region, or their own infrastructure entirely, can self-host the open-source edition.
- Vulnerability reports
- Reports go to a monitored security mailbox and are triaged on receipt. We do not run a paid bounty, and we do not pursue good-faith researchers.
Documentation
Security and legal documents
Published rather than sent on request, so a review can start without waiting on us.
Frequently asked questions
Report a security issue
If you believe you have found a vulnerability, or you have a question about our security practices, write to us. We acknowledge a report within two business days. The responsible disclosure policy sets out scope and what you can expect from us.
Healthy suspicion
Trusts nothing it can't verify
Every answer is grounded in your sources and cited, tenants are isolated at the database row, and anything it can't back up never reaches a visitor.
Read the security page
