Security & privacy

Your research stays yours.

You are putting client material into this. Isolation, identity and a complete audit trail are architectural decisions in the Hub — not settings you have to remember to switch on.

Private end to end

The Hub is invitation-only. Every request is checked against your session — there is no shared or public password, and nothing is reachable without signing in as yourself.

Accounts are isolated

Content belongs to an account. Accounts cannot see one another’s projects, sources, workflows or outputs. There is no cross-account search.

Prototypes run sandboxed

Interactive prototypes execute in a locked sandbox with no network access, no cookies, and no reach into the rest of the page.

Everything is audited

Account and user administration, workflow runs, publishing and visibility changes are all recorded with who did it and when.

Your questions stay server-side

AI calls are made from our backend rather than your browser, and answers are grounded in the material you supplied rather than the open web.

Content capture is controllable

Diagnostics can be run on metadata alone — timings, token counts and cost — with prompt and response text excluded entirely.

Built to be reviewed

Controls you can point your security team at, not a list of adjectives.

Doing vendor due diligence? Send your security questionnaire during the access conversation. We answer it directly, in writing, with the architecture behind each answer — and we tell you where a control is roadmap rather than shipped, because that is what makes the rest of the document worth reading.

The Hub is ready. Access is by invitation.

We work with a deliberately small group of researchers — close enough that the Hub is built around how the work is actually done. Tell us what you research and we'll be in touch.

Request an invitation