SECURITY & PRIVACY

Enterprise controls without the enterprise drag

Your knowledge is your business. BeforeQuery isolates every workspace, masks PII before content reaches any LLM, never trains models on your data, and ships the SSO, audit, and permission controls your security review will ask about.

Controls that matter

The security posture behind every deployment

Isolated by design

Data Protection

  • Workspace isolation for content, embeddings, and chats
  • Encryption in transit and at rest
  • PII masked before any LLM call
  • Your data is never used to train models
  • Delete a source and its indexed content goes with it
Your IdP, your rules

Identity & Access

  • SSO via OIDC and SAML 2.0
  • Per-knowledge-base permissions for members
  • Restricted document visibility within a knowledge base
  • Client keys with scoped, revocable access
  • Allowed-groups enforcement on integration keys
Reconstruct anything

Auditability

  • Workspace audit logs for admin actions
  • Conversation history with citations
  • Traces of retrieval behind every answer
  • Approval queues and invocation logs for AI Actions
  • Signature verification on every webhook
Safe by architecture

Grounded answers are a security feature

The biggest AI risk in customer-facing deployments isn't a breach — it's the assistant confidently saying something your company never approved. BeforeQuery's architecture answers only from content you indexed, cites it, and falls back transparently otherwise. Combined with human approval on AI Actions, the blast radius of any single answer stays small.

  • Answers bounded by your approved, indexed content
  • Citations make every claim verifiable
  • AI Actions gated by approval rules and review queues
  • Public surfaces retrieve only public documents
  • Enterprise plan adds advanced governance and SSO enforcement

Frequently Asked Questions

Common questions about Security & Privacy

No. Indexed content, embeddings, and conversations stay isolated to your workspace and are used only to answer your own questions. Nothing is shared across customers or used for model training.
Personally identifiable information in questions is masked before content reaches the LLM, and conversations are stored with that masking applied. Data is encrypted in transit and at rest.
OIDC and SAML 2.0 connections are supported per workspace, so employees authenticate through your identity provider. Enterprise plans include SSO alongside audit logs and advanced governance.
Three layers: separate knowledge bases for public and internal content, per-knowledge-base permissions for members, and restricted document visibility within a knowledge base. Public widgets and API keys retrieve only public documents.
AI Actions run under approval rules you define — sensitive invocations go to a human-approval queue and every invocation is logged. Nothing touches your systems without the policy you configured.

Bring it to your security review

Read the security overview, or talk to us about enterprise requirements.

Get Started Free