Enterprise
Controls that are enforced, not described
Organizations, workspaces and six roles, with authorization enforced on the server and again in the database. A control that only exists in the interface is not a control.
The control plane
Organizations and workspaces
Work is owned by a workspace, not by whoever happened to create it. People come and go without taking the work with them.
Six roles
Owner, Admin, Builder, Member, Viewer and Billing. Viewer cannot run anything, because running spends money. Billing sees spend and nobody's work.
Tenant isolation
Enforced by row-level security as well as application code, and tested as an unprivileged database user rather than assumed.
Append-only audit
Membership changes, key creation, publishes and approvals. Audit rows cannot be edited or deleted, by anyone.
Usage and budgets
Provider cost, customer charge and margin kept as separate concepts. Corrections are new entries, never edits.
Model policy
Which providers and models a workspace permits, with privacy-constrained routing where required.
What we do not claim
We do not hold SOC 2 or ISO certification, and we do not offer SAML, SCIM or regional data residency today. We are saying so on our own website because you would find out in procurement anyway, and a vendor who overstates this one is overstating others.
If any of those is a requirement, talk to us about timing before you invest evaluation effort.
Selecting any of these opens an enquiry. It is not an application, it does not accept a sponsorship, and it does not take a payment. Public contact addresses are still being set up — if you reached us through a partner or an invitation, replying on that thread is the fastest route.