Identity and access
Sandbox and console access are gated behind Authentik. API integrations use scoped bearer keys rather than browser sessions.
The commercial site is static and public. Anything involving documents, conversations, billing, API keys, or usage data is routed behind authenticated access.
Sandbox and console access are gated behind Authentik. API integrations use scoped bearer keys rather than browser sessions.
Documents and retrieved chunks are scoped to each organization. Customer corpora are private by default.
Usage events capture model id, token estimates, retrieval count, latency, user/API key, and backend cost estimate.
Models can be hosted on dedicated GPU backends or customer-controlled infrastructure where procurement requires it.
| Surface | Control | Data touched |
|---|---|---|
| Commercial website | Public Cloudflare Pages | No customer private data |
| Sandbox and console | Authentik login and registration | Documents, chat history, API keys, billing |
| Customer API | Scoped API keys | Prompts, retrieved source chunks, model outputs |
| Large models | Approval windows and gating | High-cost inference requests |