Security

Choose memory with clear boundaries.

Give your agent access to the context it needs. Enscrive combines scoped API keys, authenticated service calls and signed releases with access controls and review of changes. Confirm the deployment details that matter for your workload.

Access and service boundaries

Enscrive uses API keys for application access and a portal for people. Tenant and environment scoping, service authentication and access controls are parts of the platform design. Configure your integration for the intended environment and keep credentials out of prompts and shared notes.

Processing your content

Embedding and optional language-model processing can send submitted content to the selected providers. A provider API key changes how you access that provider; it does not keep processing inside the Enscrive deployment.

Confirm provider policies and processing locations for your workload. See our Privacy Policy.

Deployment and residency

Managed early access is available by arrangement. Discuss the hosting region, networking, access controls and recovery requirements for your deployment. A hosting region is not an end-to-end data-residency guarantee for external providers.

Dedicated infrastructure and additional controls are matters for availability and contract discussion, not automatic plan entitlements.

Security review before sensitive use

We use code review and testing to check changes, including access-controlled data paths. We have not completed an independent SOC 2 or ISO 27001 audit.

Review credential handling, transport and storage protection, logging, networking, backups and recovery with us for your deployment. These details determine whether the setup fits your sensitive-data requirements.

Ownership and use of content

You retain ownership of your content. We do not sell or lease your data, and we do not share it with analytics companies. Under our Terms, we do not use Customer Content to train general-purpose models without an explicit written agreement.

Service-provider processing is described in our Privacy Policy. Your selected provider’s terms and settings also govern its processing.

Incident communication

Security incident notification: 72 hours, or sooner where applicable law or your agreement requires.

Responsible disclosure

We welcome security researchers. If you discover a security issue, please report it to support@enscrive.io.

We commit to:

  • Acknowledge receipt within 24 hours
  • Provide initial assessment within 72 hours
  • Keep you informed of remediation progress
  • Credit researchers (if desired) upon fix deployment

Please do not publicly disclose vulnerabilities before we have had a chance to address them, and do not access or modify data belonging to other users.