Phishing-resistant sign-in
A physical key instead of a code. There is nothing left for an attacker to talk someone into reading out.
A certificate says an auditor looked once. These are the three things a customer's security team actually asks about.
A physical key instead of a code. There is nothing left for an attacker to talk someone into reading out.
Sensitive records are anonymised first, so what leaves is the question and not the person behind it.
Every write is timestamped in an immutable log, kept for ten years, and readable as a report.
From sign-in to the report, six steps. Nobody has to see a real record to do their part.
SSO and OAuth with a hardware security key. A magic link covers the one-off external collaborator.
Uploads run through the API or the customer's portal, never as an attachment in somebody's inbox.
Frankfurt, US East or Melbourne. The region follows your customers, not our convenience.
A data engineer can pull an export and work on it locally. Since the records identify nobody, that copy carries far less risk than the original.
Claude, ChatGPT or Cursor reach the platform through MCP and see the same anonymised basis. No separate environment and no separate rules.
Every change is written immutably, and the reports turn that into something an auditor can read on their own.
Every headline backed by a concrete workflow. Screenshots show what your team will actually use.
Sign-in can be bound to a physical security key: YubiKey, Google Titan or Feitian. A code can be talked out of someone on the phone, a key cannot. An authenticator app and recovery codes cover the rest.
Sensitive fields are masked or swapped for plausible substitutes, and the structure stays identical. A model gets an answerable question, and your data engineers build the migration against records that identify nobody.
20-minute call. Bring the one your last customer sent, and we go through it line by line.
Anonymised input, processing in your own region, every action in the audit trail. And if your security team has already cleared Claude or ChatGPT, you connect that one over MCP rather than putting another vendor through procurement.
Data goes up over a secured channel and stays in the region you picked: Frankfurt, US East or Melbourne. A region we do not run yet is a setup question, not an architecture one.
Every write lands in an immutable audit trail: timestamped, per tenant, kept for ten years. The reports turn that log into something an auditor reads without asking anyone to explain it.
Anonymised from our customer base. See whether one of them is yours.
Your customer's compliance team sends a security questionnaire, and half of it is about the platform you run on rather than about you.
Sign-in, processing region and audit trail are answered from one page, instead of three internal emails and a two-week wait.
A prospect in a regulated field asks how safe your AI is in the first call, before anyone has shown a single feature.
Anonymisation, region and the audit trail answer it on the spot, and the conversation goes back to the product.
Expansion into another country brings a customer whose regulator has an opinion about where their records are stored.
The region is chosen per customer, so the answer is a setting rather than a project.
Three habits that turn security into a delay instead of an answer.
Other parts of the platform you'll use alongside this.
SSO and OAuth federation with a hardware security key. For a one-off external collaborator, an agency or a contractor, a magic link avoids an account nobody uses twice.
Anonymised records. The anonymisation happens before anything reaches a model, so the customer behind the data never leaves the platform.
In the region you choose: Frankfurt, US East or Melbourne. If your customers need a region we do not run yet, adding one is a setup question.
Every write, timestamped and attributed, in an immutable trail kept for ten years. It is the same trail the migration reports are built from.
20-minute call. Show us your source, we show you the mapping. No deck required.