DocketX

DocketX / Security and data

Security and data

Every in-house security review asks the same four questions. Here are our answers, stated plainly enough to forward, plus the option that makes most of them moot: run the whole engine inside your own perimeter.

The short version

Four questions every security review asks

Do you train on our data?

No. Matter content stays in its matter and never enters the shared library. We do not train on customer content.

Where does our data go?

To the model you chose, and to our own library for retrieval. You pick the model per key, including private models on your own hardware, where the answer is nowhere.

What do you keep?

The request ledger that makes the audit trail possible, plus anything you deliberately upload to a matter. The data policy states it precisely.

Can we run it ourselves?

Yes: private inference, private-pod keys the gateway enforces, your models, your hardware, same citation gate.

Hostile documents

Matter files are scanned for embedded instructions (prompt injection); hostile documents are quarantined rather than obeyed.

Keys and access

Header-only API keys, per-key spend caps, per-key jurisdiction and data-policy settings, OAuth PKCE issuance for third-party apps, and encrypted-at-rest storage for bring-your-own provider keys.

Honest posture

What we do not claim

We are a young company and will not decorate this page with certifications we do not hold. What we offer instead is specificity: a published data policy, a per-request audit trail you can inspect, a coverage API that reports our own limits, and the option to run the entire engine inside your perimeter so the trust question becomes moot. If your review needs something we have not built, tell us and we will say plainly whether it exists.