Access and service boundaries
Enscrive uses API keys for application access and a portal for people. Tenant and environment scoping, service authentication and access controls are parts of the platform design. Configure your integration for the intended environment and keep credentials out of prompts and shared notes.
Processing your content
Embedding and optional language-model processing can send submitted content to the selected providers. A provider API key changes how you access that provider; it does not keep processing inside the Enscrive deployment.
Confirm provider policies and processing locations for your workload. See our Privacy Policy.
Deployment and residency
Managed early access is available by arrangement. Discuss the hosting region, networking, access controls and recovery requirements for your deployment. A hosting region is not an end-to-end data-residency guarantee for external providers.
Dedicated infrastructure and additional controls are matters for availability and contract discussion, not automatic plan entitlements.
Security review before sensitive use
We use code review and testing to check changes, including access-controlled data paths. We have not completed an independent SOC 2 or ISO 27001 audit.
Review credential handling, transport and storage protection, logging, networking, backups and recovery with us for your deployment. These details determine whether the setup fits your sensitive-data requirements.
Ownership and use of content
You retain ownership of your content. We do not sell or lease your data, and we do not share it with analytics companies. Under our Terms, we do not use Customer Content to train general-purpose models without an explicit written agreement.
Service-provider processing is described in our Privacy Policy. Your selected provider’s terms and settings also govern its processing.
Incident communication
Security incident notification: 72 hours, or sooner where applicable law or your agreement requires.
Responsible disclosure
We welcome security researchers. If you discover a security issue, please report it to
support@enscrive.io.
We commit to:
- Acknowledge receipt within 24 hours
- Provide initial assessment within 72 hours
- Keep you informed of remediation progress
- Credit researchers (if desired) upon fix deployment
Please do not publicly disclose vulnerabilities before we have had a chance to address them,
and do not access or modify data belonging to other users.