Skip to content

Enterprise

Controls that are enforced, not described

Organizations, workspaces and six roles, with authorization enforced on the server and again in the database. A control that only exists in the interface is not a control.

The control plane

Organizations and workspaces

Work is owned by a workspace, not by whoever happened to create it. People come and go without taking the work with them.

Six roles

Owner, Admin, Builder, Member, Viewer and Billing. Viewer cannot run anything, because running spends money. Billing sees spend and nobody's work.

Tenant isolation

Enforced by row-level security as well as application code, and tested as an unprivileged database user rather than assumed.

Append-only audit

Membership changes, key creation, publishes and approvals. Audit rows cannot be edited or deleted, by anyone.

Usage and budgets

Provider cost, customer charge and margin kept as separate concepts. Corrections are new entries, never edits.

Model policy

Which providers and models a workspace permits, with privacy-constrained routing where required.

What we do not claim

We do not hold SOC 2 or ISO certification, and we do not offer SAML, SCIM or regional data residency today. We are saying so on our own website because you would find out in procurement anyway, and a vendor who overstates this one is overstating others.

If any of those is a requirement, talk to us about timing before you invest evaluation effort.

Selecting any of these opens an enquiry. It is not an application, it does not accept a sponsorship, and it does not take a payment. Public contact addresses are still being set up — if you reached us through a partner or an invitation, replying on that thread is the fastest route.