DocketX / Security and data
Every in-house security review asks the same four questions. Here are our answers, stated plainly enough to forward, plus the option that makes most of them moot: run the whole engine inside your own perimeter.
The short version
No. Matter content stays in its matter and never enters the shared library. We do not train on customer content.
To the model you chose, and to our own library for retrieval. You pick the model per key, including private models on your own hardware, where the answer is nowhere.
The request ledger that makes the audit trail possible, plus anything you deliberately upload to a matter. The data policy states it precisely.
Yes: private inference, private-pod keys the gateway enforces, your models, your hardware, same citation gate.
Matter files are scanned for embedded instructions (prompt injection); hostile documents are quarantined rather than obeyed.
Header-only API keys, per-key spend caps, per-key jurisdiction and data-policy settings, OAuth PKCE issuance for third-party apps, and encrypted-at-rest storage for bring-your-own provider keys.
Honest posture
We are a young company and will not decorate this page with certifications we do not hold. What we offer instead is specificity: a published data policy, a per-request audit trail you can inspect, a coverage API that reports our own limits, and the option to run the entire engine inside your perimeter so the trust question becomes moot. If your review needs something we have not built, tell us and we will say plainly whether it exists.