Native data loss prevention
Secrets never touch plaintext chat.
Capability-based access control and row-level security throughout, with a secrets manager so credentials are never pasted into a channel.
What it does
- Credentials live in the secrets manager and are referenced, not pasted.
- Row-level security applies to every query, including the AI layer's.
- Access is granted as a capability, revocable without a migration.
What that means in practice
Credentials are referenced, not pasted
Credentials live in the secrets manager and are referenced. They do not enter a channel as text.
Row-level security includes the AI
Row-level security applies to every query, including the ones the AI layer makes. The layer cannot read past a boundary a person could not.
Access is a capability
Access is granted as a capability and can be revoked without a migration.
Limits
Documented here as a guarantee rather than a mechanism: this page is public (KB_PLAN.md 12.6), so it states what the control ensures and not how enforcement is implemented.
Where to go next
- The rest of the trust pillar
- Plans and pricing for what each tier includes
Related guides · Security & data protection
Updated 2026-08-19