Every project, document, action and review belongs to exactly one account. Cross-account access is blocked by the data layer, not by hiding a button.
Uploads are never served from a guessable address. Downloads go through short-lived signed links tied to your session.
Who ran what, who spent which credits, who uploaded what and who was invited — recorded and visible to your account administrator.
On team plans you decide who can run actions, who can only read, and whether a person has a credit ceiling of their own.
A privacy page that only makes promises is not a privacy page. Here is the other half.
No SOC 2, no ISO 27001, no penetration-test badge. If your procurement requires one, we are not a fit today and we will say so rather than imply otherwise.
A technical security review finds technical problems. It does not tell you whether you comply with a regulation, and it is not a substitute for counsel.
A review needs a reader. If a document is too sensitive to be read by someone outside your company, do not upload it — run the procedure and keep the result.
Classification, generation and verification involve language models. Human expert review involves a person. The workspace always shows which one produced what you are reading.
Run the procedure in your own environment and share only what you decide to share.