Skip to main content
$ platform / security-sovereignty

Security & Sovereignty.

Multi-tenant isolation at the query layer. 334 ACL policies. Immutable audit. EU-hosted.

The problem.

Vendors sell security as a tier.

We treat it as an invariant: every write produces an audit event, or the request fails.

Our approach.

[01]

Isolation at the query layer

Tenant scope is a primary key, not a convention.

[02]

Immutable audit

Pipeline invariant — no write without an event. Append-only, hash-chained.

[03]

EU data sovereignty

EU-hosted; most AI runs on self-hosted models in our EU datacenter, with a cloud fallback and two features primary on a US provider — every provider is listed on the subprocessors page. GDPR by architecture. NIS2-ready.

[04]

Published disclosure

security.txt, PGP key, bug bounty. We disclose when we are wrong.

See it in production.