Security

Security you can trace

Ciele is built so organizations can trust their AI assistants: tenant data is isolated at the database layer, access is scoped by role, answers are grounded in your own knowledge, and your content is never used to train models.

SOC 2 Type IIin progress
GDPR compliancein progress

We recently began our SOC 2 Type II and GDPR compliance programs. Those certifications are not complete yet, and we will not claim otherwise. The practices below are in place today.

Tenant isolation by default

Every organization's data is separated at the database layer. Access is enforced with Postgres row-level security, so one tenant can never read another tenant's assistants, knowledge or conversations.

Role-based access control

Members are assigned roles that scope what they can see and change within their organization. Sign-in is handled through our managed authentication layer, with single sign-on through Google and Microsoft.

Encryption in transit and at rest

Traffic to the platform is served over TLS, and data is encrypted at rest by our managed database and storage providers. Secrets and access tokens are stored sealed, never in plain text.

Your data is never used to train models

The content and conversations flowing through your assistants are used only to answer questions for your organization. We do not use them to train foundation models, and we do not share them with other customers.

Grounded, auditable answers

Assistants answer from the knowledge you connect and cite the exact Source behind each response, so every answer can be traced back to the page or document it came from rather than an opaque model guess.

Secure integrations

Connections to knowledge sources, help desks and identity providers use scoped credentials that are sealed at rest. Operational alerts flag an integration whose credentials stop working so it can be addressed quickly.

Compliance and governance

We are early in our formal compliance journey and are being deliberate about what we claim. Here is where things stand:

  • SOC 2 Type IIProgram recently started. We are defining and implementing the controls needed for an audit of security, availability and confidentiality.
  • GDPRCompliance work underway. We honor data access and deletion requests today and use Standard Contractual Clauses for international transfers.
  • Data processingWhen customers run their own assistants, Ciele acts as a processor and the customer is the controller of their conversation and end-user data.
  • SubprocessorsA short list of hosting, database and model providers process data on our instructions. We can share the current list on request.

Frequently asked questions

Is Ciele SOC 2 certified?

Not yet. We have recently started our SOC 2 Type II program and are putting the controls and evidence in place. We will update this page as we progress and can share more detail with prospective customers under NDA.

Is Ciele GDPR compliant?

We have begun formal GDPR compliance work. In practice we already follow its core principles: data minimization, tenant isolation, encryption, and honoring data access and deletion requests. Where we transfer data internationally we rely on Standard Contractual Clauses.

Who can access our organization's data?

Within your organization, access is governed by the role each member holds. On our side, access is limited to the small number of staff who need it to operate and support the service, on a least-privilege basis.

Do you use our data to train AI models?

No. Your knowledge and conversations are used only to run your assistants and to generate answers for your organization. They are not used to train foundation models.

Can we delete our data?

Yes. Organizations control the conversation and knowledge data their assistants collect and can delete it from within the product. On account closure we delete or return your data subject to any legal retention requirements.

Where is our data processed?

The platform runs on managed cloud infrastructure and uses a small set of subprocessors, including our hosting, database and model providers, to deliver the service. We can share our current subprocessor list on request.

Report a security issue

If you believe you have found a vulnerability, or you have a question about our security practices, please reach out. We take reports seriously and will respond quickly.

security@ciele.app