Security by design, not as an optional
WorkspaceAi is built for organizations that cannot delegate their data to a shared platform. Perimeter control, per-Assistant segregation, and centralized governance — from deployment to daily operations.
Principles
Four pillars of security
A consistent model for CISOs, IT, and business owners — no compromise between AI utility and data control.
Data sovereignty
Documents, conversations, and configurations remain within the perimeter chosen by the client — on-premise or private cloud, with no shared multi-tenant platform.
Least privilege
Explicit access per user, App, and automation. No resource is visible unless assigned by the administrator.
Per-App isolation
Each Assistant maintains segregated knowledge bases, chat history, integrations, and credentials — clear boundaries between teams and domains.
Defense in depth
Encryption of secrets at rest, protected channels in transit, document uploads without plaintext transit on the application server.
Governance
Access control and roles
Two-tier enterprise model — administrators configure, end users operate only on authorized resources.
- Separate Admin and User roles with distinct scopes (configuration vs usage)
- Explicit App assignment per user or group
- Permissions on automations, integrations, and selectable models
- Immediate access revocation from the admin panel
Data
Protection and segregation
Company data does not flow into a shared pool: each App has dedicated boundaries for content, metadata, and files.
- Knowledge bases, embeddings, and conversations isolated per Assistant
- Document storage with dedicated paths per App
- No cross-tenant reuse of trained content
- Document deletion and updates with controlled re-indexing
Secrets
Credentials and integrations
API keys, MCP tokens, and sensitive variables managed centrally and protected at rest — decrypted only server-side at time of use.
- Secrets never exposed to the frontend or user browser
- Credential rotation and updates without redeploying the entire platform
- MCP integrations with credentials segregated per App
- Principle of least access toward connected external systems
Deploy
On-premise or private cloud
WorkspaceAi is designed for enterprise environments: installation in the client's data center or VPC, with negotiable network and compliance requirements.
- Self-hosted or cloud-managed deployment within the client's perimeter
- On-site AI inference option, with no data leaving to external services
- Compatible with corporate network policies, firewalls, and proxies
- Support for air-gapped scenarios and regulated environments
Operations
Traceability and audit
Visibility into sensitive operations for IT and compliance teams — without compromising chat content confidentiality.
- Administrative logs on configuration, users, and integrations
- Tracking of automation executions and App access
- Documented procedures for backup, restore, and disaster recovery
- Alignment with client audit and due diligence requests
Compliance
Ready for regulated environments
WorkspaceAi integrates into the client's compliance processes — privacy, audit, and vertical sectors with stringent requirements.
GDPR and privacy
Data processing within the controller's perimeter. Option to limit content use to the Assistant's purpose only, with no cross-client training.
Regulated sectors
Architecture suited to scenarios with elevated requirements (finance, healthcare, public sector) — deployment and controls customizable per contract.
Due diligence
Technical and commercial documentation available for security assessment, RFPs, and client IT team review.
Next step
Do you have specific security requirements?
Together we'll define deployment perimeter, data segregation, and operational controls for your enterprise context.