Trust
Your knowledge is the asset. It stays yours.
For a regulated European enterprise, sovereignty is not a preference — it is the condition of being allowed to use any of this at all. So it is where the platform starts rather than something bolted on for the security review.
Deployment
Three places it can run
The same product in all three. What changes is whose boundary it sits inside.
Hosted by us
Most teams, and every Foundation workspace
Multi-tenant SaaS, run on our infrastructure. Fastest to start, nothing to operate, and the option every self-serve signup lands on.
Your own cloud
Data residency, existing cloud commitments
The same platform deployed into your tenancy, so the data never leaves an environment you already control and already audit.
On premises or sovereign
Regulated, classified, or contractually constrained
Your hardware, your network, your boundary. Sales-led — never self-serve — because it is the one place the software itself is installed rather than reached.
Precision, deliberately
Air-gappable, not air-gapped.
Those are different words and we use the accurate one. The whole platform can run with no network path out: ingestion, the knowledge layer, administration and coordination all deploy inside your boundary, on your own hardware.
Whether a given deployment is air-gapped depends on how you run it, and it is a claim about your estate rather than about our software. We will not make it for you.
Encryption and classification are always on
Not a tier and not a toggle. Classification is how the access system works, so there is no configuration in which it is switched off and no edition in which you are without it.
Your model, your contract
Bring your own model and inference stays between you and your provider at your rate. We do not proxy your prompts to resell tokens.
Every fact carries its provenance
Source, author, date and scope travel with the fact. When something turns out to be wrong you can find what rested on it, which is the difference between a correction and an incident.
Facts supersede rather than accumulate
When the organisation changes its mind, the old fact is superseded and dated, not silently overwritten. The record of what was true when remains.
Operations
Where it runs, and how it is looked after.
The questions a security reviewer opens this page to answer, answered here rather than in a questionnaire three weeks later.
Hosted in the jurisdiction you need
Hosted by us, the platform and its backups are placed in the jurisdiction your policy requires. In your own cloud or on your own hardware, the boundary is already yours. Backups stay in the same jurisdiction as the data they protect, so there is no cross-border transfer to account for.
Backups you can prove, not backups you hope for
Encrypted before they leave our hands, so the storage provider cannot read them even in principle. We back up logical database dumps rather than live database files, because a live file copied mid-write is not a backup. Integrity is checked weekly.
Restores are drilled, not assumed
A backup nobody has restored is a belief, not a control. Every database is restored into a throwaway environment on a schedule and checked for its real contents before the drill is called a pass.
One front door for identity
Staff and product access sit behind a single sign-on provider rather than a set of separate logins. Access is granted per person and removed in one place.
Access control survives distillation
A fact distilled out of a restricted document inherits that document's access, rather than becoming a loose sentence anyone can retrieve. Verified against the running system in August 2026.
Deletion distinguishes why
A document being wrong, a document being withdrawn and a person exercising their rights are three different events with three different outcomes. The system treats them as different rather than collapsing them into one delete.
Bring your security team.
The questions they ask are the ones this was built around. We would rather have that conversation early than at the end.