Security & Trust

Security Engineered at Every Layer

Indexu is built with strict workspace isolation, zero-knowledge AI privacy, and enterprise-grade compliance from the ground up.

GDPR Ready
Full data control
SOC 2-Aligned
Control-based security
Data Residency
EU & US options
Zero Training
No AI data sharing
99.98% Uptime
High availability
Architecture

Workspace Isolation

Data bleeding is structurally impossible. Indexu enforces workspace isolation at the data layer, not just at the application logic layer.

  • Fail-Closed Global Scopes: every resource is scoped by workspace_id. Queries are automatically filtered: WHERE workspace_id = [context].
  • WorkspaceContext Singleton: safely maintains the current workspace context throughout the entire request lifecycle.
  • BelongsToWorkspace Trait: enforces strictly automated attachment and retrieval of models to their owner workspace.
HTTP Request
Middleware
(Resolve Workspace + Verify Membership)
WorkspaceContext (Singleton)
Model Global Scope
WHERE workspace_id = context
Database Query

Zero Training Opt-In by Default

Your data is never used to train or fine-tune public language models. It remains strictly within your workspace boundary.

Partitioned pgvector Storage

Vector embeddings are securely stored in a partitioned PostgreSQL environment, ensuring search queries only operate on your distinct data.

Local Inference Ready

For maximum privacy, point Indexu at any OpenAI-compatible endpoint (including self-hosted inference servers) so AI tasks never leave your infrastructure.

AI Privacy

Zero-Knowledge AI & Data Governance

We employ privacy-first AI. Indexu runs isolated embedding and inference loops that prevent model training on workspace data and secure resource usage with atomic token quotas.

  • Zero model training on your data
  • Workspace-partitioned pgvector storage
  • Atomic token quota reservations
  • Air-gapped on-premise deployments
Access Control

Instant Suspension Kill-Switch

Protect your organization instantly. With a single action, revoke access across every vector of your workspace to guarantee zero leakage.

  • Session & Token Revocation: invalidate active web sessions and Sanctum API tokens globally.
  • Job & WebSocket Termination: immediately halt queued background jobs and realtime WebSocket connections.
  • Webhook & API Key Disablement: suspend incoming webhooks and outgoing API integrations instantly.
System administrator dashboard with workspace oversight
Suspension controls that block all backend activity instantly
Cryptography

Cryptographic Verification

Data integrity is verified cryptographically at every integration point, ensuring malicious actors cannot spoof webhooks or access private files.

  • HMAC-SHA256 Webhook Verification: incoming payloads from providers like WhatsApp and Twilio are strictly validated against secure hashes.
  • Private Dual-Bucket Storage: public assets are separated from private attachments, which are only accessible via short-lived signed URLs.
  • One-Time API Key Displays: API keys are revealed once upon creation, then irreversibly hashed in the database.
Compliance

Audit & Compliance Logs

Maintain complete visibility over your workspace with immutable logs. We track every significant action to simplify compliance and internal reviews.

  • Immutable Audit Trails: append-only logging guarantees the history of changes remains tamper-proof.
  • Comprehensive Context: every event captures the user, role, IP address, user agent, timestamp, and action details.
  • Admin Action Visibility: cross-workspace admin actions and role changes are explicitly flagged and audited.

Security Audit Log

API Key Generated

By Sarah Connor • IP: 192.168.1.104

2 mins ago

Role Elevated to Admin

For John Doe by Admin • IP: 10.0.0.5

1 hour ago

Successful Login

By Jane Smith • Mac OS / Chrome

3 hours ago

Download our security whitepaper for a detailed architecture review.

Get comprehensive insights into our data handling, infrastructure security, and compliance posture.

Request Security Documentation

Have security questions? Let's discuss.

Our security engineering team is ready to address your custom compliance requirements and architectural questions.