Trust Center

Security and compliance controls for agent AI workflows.

AgentAssist is built around organization boundaries, source-backed AI, audit evidence, and operational visibility for teams that need reviewable answers.

Tenant-scoped access

Organization membership, roles, and permission checks guard documents, AI conversations, billing, settings, and admin workflows.

Source-grounded AI

RAG responses include retrieval metadata and citations, with no-context and no-advice guardrails for customer-facing workflows.

Audit evidence

Sensitive actions such as uploads, deletes, exports, billing changes, support access, and SuperAdmin settings are logged.

Operational readiness

Worker queues, retry controls, performance snapshots, security audit gates, and retained load evidence are tracked for release readiness.

Data handling summary

Customer documents are organization-scoped and used to power retrieval, summaries, comparisons, analytics, and compliance workflows. They are not used to train public foundation models.

Trust documents

Review the core legal, privacy, support, subprocessor, and status resources used during customer security review.

Identity and access

  • Authenticated access through Better Auth session controls.
  • Organization membership required for tenant resources.
  • Role and permission checks for billing, settings, documents, exports, and SuperAdmin surfaces.
  • Support access is intended to be reasoned, limited, and auditable.

Document and AI handling

  • Uploaded documents are scoped to the owning organization.
  • Document chunks and citations are used for retrieval-grounded answers.
  • Customer documents are not used to train public foundation models.
  • AI output is assistance only and must be reviewed against source documents.

Infrastructure and storage

  • Dev deployment uses isolated SaaS, Marketing, worker, Postgres pgvector, and object storage services.
  • Signed upload and view flows avoid exposing raw storage keys to the browser.
  • Database migrations run before the SaaS app starts.
  • Worker queues and retry controls support document ingestion resilience.

Compliance evidence

  • Sensitive write paths are designed to produce audit evidence.
  • Deletion workflows track request, review, purge, actor, and retention context.
  • Billing state, usage, and failed-payment controls are organization-scoped.
  • Operational runbooks and retained evidence support release review.
AI governance

Built for reviewable agent assistance

AgentAssist is designed to help agents find, summarize, compare, and explain approved source documents. It is not a replacement for professional advice, source approval, human review, or compliance review.

  • Source-grounded summaries and comparisons should cite the documents used.
  • No-context and no-advice rules prevent the copilot from pretending to know facts that are not in the workspace.
  • Prompt-injection checks are intended to protect hidden instructions, tenant data, and credentials.
  • Structured artifacts remain reviewable before they are exported, shared, or saved as reusable facts.