Skip to main content
Security & isolation

Boring by design. Isolated by architecture.

Workspace isolation is enforced in the database, not in application code. We're building toward SOC 2 - and we label what hasn't shipped yet, honestly.

Controls

RLS workspace isolation

Row-level security scopes every query to its workspace. Cross-workspace access is structurally impossible, not just policy.

TLS everywhere

Encrypted in transit across every surface - workspace, API, and SSE streams.

No training on your data

Your documents ground answers; they are never used to train models. Full stop.

API key scoping

Keys scoped per app and per agent, sessions isolated by app_id, rotation one click away.

Human-in-the-loop

Plan-mode proposals wait for sign-off; agent tool use is allowlisted per agent.

Run logs & audit trail

Every session, run, and approved plan is timestamped and reviewable in the console.

Data residency options

Choose where storage and inference run - Canadian and US regions across multiple clouds.

Drafts wait. Humans decide.

Customer-facing actions pause at an approval gate. A person clears them, and every step lands in an append-only audit trail you can export for review.

Agent drafts the reply

refund request · ticket #4,821

Held at the gate

nothing sends itself

Awaiting human

Approved by Priya N.

sent, and logged

hitl.approve @priya

audit.append run #9,304

Compliance
RLS isolationEnforced at the database layer for all workspace dataShipped
TLS in transitAll traffic encrypted, including SSE streamsShipped
Encryption at restAES-256 on databases and file storage, managed by the backing cloudShipped
Data retentionDeleted files and sessions purged within 30 days; export anytime beforeShipped
No-training guaranteeContractual: customer data never trains modelsShipped
SOC 2 Type IIControls being implemented toward certification - not certified todayTargeting
SSO / SAMLEnterprise identity providersRoadmap
SCIM provisioningAutomated user lifecycle managementRoadmap

Ask us the hard questions.

Security review, data-processing terms, or residency in your own cloud - we'll answer straight.

Or email contact@sundaypyjamas.com - a founder replies.