Your knowledge stays yours.
Corpussage indexes your content to answer questions. It does not store, train on, or share your data. Everything is encrypted in transit and at rest, with permission boundaries that mirror your existing access controls.
Built for teams that handle sensitive information
Security is not an add-on. These controls ship in every plan.
Encryption at rest and in transit
All indexed content is encrypted at rest using AES-256. Data in transit is protected by TLS 1.3. Encryption keys are rotated automatically on a rolling schedule.
Permission-aware indexing
Corpussage respects your existing source permissions. If a user cannot see a document in Confluence, they cannot surface it through Corpussage answers either. Access boundaries are enforced at query time.
SOC 2 controls in design
We are a bootstrapped team building toward SOC 2 Type II. Our infrastructure and access controls are designed to the SOC 2 framework. We share our trust documentation with teams evaluating enterprise plans.
No training on your data
Your team's documents and answers are never used to train AI models, including our own. Your knowledge base remains private to your organization. This is a hard architectural commitment, not a setting.
Audit logs
Every answer, source lookup, and admin action is logged. Teams and Growth plan customers can export query logs for compliance review. Enterprise customers get log streaming to their own SIEM.
Data residency options
All data is hosted on AWS in the US-East region by default. Teams on the Teams plan can request EU data residency for GDPR compliance. Residency selection is set at workspace creation.
Privacy compliance
We are transparent about what we support and what we are working toward. No false certifications.
GDPR
Corpussage supports GDPR compliance for EU-based teams. You can request data deletion for any workspace. User data is not shared with third parties for marketing. Data processing agreements are available on request.
CCPA
California users have the right to know what data is collected and to request deletion. We collect only the data needed to answer your questions: indexed content, query logs, and account information. No data is sold.
What we index
We index document content, titles, metadata, and access permissions from your connected sources. We do not read email, calendar, or any source you have not explicitly connected. You can disconnect any source and delete its index at any time.
Subprocessors
Our current subprocessors for AI inference and hosting are AWS and Anthropic. We maintain a current subprocessor list and notify customers of changes 30 days in advance. GDPR data processing agreements are in place with all subprocessors.