Servly

Security and guardrails

A persona that speaks for your organization has to stay inside clear limits. Here is how the engine keeps data separated, protects personal information and keeps the AI in bounds.

Isolation

  • Every database query is scoped to a tenant, and stored files are separated per tenant.
  • Each knowledge base has its own search index, so content never leaks between personas.
  • Embed keys are random, scoped to a single knowledge base, and work only on domains you allow.
  • Admin routes sit behind Cloudflare Access; API access uses per-customer keys.

Personal data

  • Phone numbers and email addresses are redacted from saved transcripts.
  • Workflows can check identity with a one-time passcode: six digits, valid for five minutes, limited attempts, single use.
  • Workflow webhooks must use HTTPS and can't point at private or internal network addresses.
  • Traffic is encrypted in transit on Cloudflare's network.

Keeping the persona in bounds

  • Answers are grounded in your own content and checked against it; the persona can only play your own media.
  • When it isn't confident, it says so, logs a knowledge gap and offers a person.
  • The browser copilot never fills passwords, one-time codes, card numbers, IBANs or national IDs.
  • Payments, submissions and deletions are pointed out and highlighted, never clicked on someone's behalf.

Control and evidence

  • Daily AI spend caps per knowledge base stop runaway costs.
  • Audit logs record administrative changes to tenants and installations.
  • An evaluation harness tests the agent against expected answers before changes go live.
  • Analytics show what was asked, answered and left unanswered; workflow data exports to CSV or JSON.

Reviews and questionnaires

We share architecture and security documentation under NDA and complete customer security questionnaires. Dedicated deployments with agreed data residency are available for regulated organizations. To report a vulnerability, email [email protected].

Bring your security team

We're glad to walk your reviewers through the architecture.