Security & Trust

AskCipher never exceeds
what you already permit.

Every action AskCipher takes is bound by the same role-based access controls as the user who initiated it. No elevated privileges. No hidden access. No exceptions.

CASA certified Other security certifications in progress Built for data privacy Configurable data retention OAuth-only authentication
Permission check Allowed
User command Update invoice terms for Meridian Global.
RoleFinance Admin
ScopeNetSuite A/R
AuditLogged

Core Principles

Six things we never compromise on.

The security architecture of AskCipher is built on principles that can't be overridden by configuration, user preference, or business need.

Inherited permissions only

AskCipher acts using the exact permissions of the authenticated user. It cannot access records the user themselves cannot access.

Zero model training

Your business data — customer records, financial data, employee information — is never used to train any AI model, public or private.

Full audit trails

Every API call, every action, every user command is logged as metadata — timestamp, identity, and outcome, never the contents. Administrators can review exactly what happened and when.

Customer-controlled data retention

Data is retrieved and retained based on your administrators' configuration and permissions. Your organization's rules decide what is kept and for how long.

OAuth-only connections

AskCipher never stores API keys or passwords. All app connections use OAuth authorization flows managed by each application's own identity provider.

Zero cross-tenant data sharing

Each organization's data and context is fully isolated. There is no shared memory or any mechanism by which data from one organization can reach another.

The permission model

AskCipher acts as the user — not as a privileged system. Every action is scoped to what that specific user is authorized to do in each connected application.

Account Exec (rep) Update Salesforce opportunity stage Allowed
Account Exec (rep) Delete a customer record Blocked
HR Manager Create BambooHR employee Allowed
HR Manager Modify payroll settings Blocked
Support Lead Close Zendesk ticket Allowed

Live Audit Log

Action log — org: acme-corp Live
14:32:17 j.chen → Updated Opportunity #00381 stage ✓ OK
14:31:44 m.torres → Created BambooHR employee ✓ OK
14:29:08 k.patel → Closed Zendesk ticket #48291 ✓ OK
14:27:52 r.kim → Attempted payroll modification ✗ Blocked
14:25:31 j.chen → NetSuite invoice staged $147,200 ✓ OK

Compliance

Meeting enterprise standards.

We build toward enterprise compliance requirements from the foundation, not as an afterthought.

CASA

Certified under the Cloud Application Security Assessment framework, with additional certifications in progress.

Data Privacy

AskCipher's data-minimization architecture is designed to align with data privacy regulations including GDPR. Data processing agreements are available for EU customers.

Data Retention

Retention is governed by your organization's configuration. Business data can be discarded immediately once a task completes.

RBAC Inheritance

All actions are scoped to the requesting user's existing permissions.

Your Data

We use the minimum.
You control what's kept.

When AskCipher runs a command, it reads only what's needed to complete the task — and retains only what your organization's rules allow.

What happens when AskCipher runs

Scoped API read

AskCipher calls your application's API using your existing OAuth session. It reads only the fields required for the specific task — nothing more.

Immediate discard

Once the task is done, all business data can be discarded immediately based on your organization's configuration.

Metadata-only logging

We log which API was called, by whom, and when — but never the contents of the response. Your audit trail is complete without ever exposing the underlying data.

What AskCipher never stores

Regardless of the command, the following categories of data are never persisted, cached, or transmitted outside your execution context — beyond what your organization's retention rules explicitly allow:

  • CRM records, contacts, and deal data
  • Financial data, invoices, and transactions
  • Personally identifiable information (PII)
  • Passwords or API keys
  • Internal communications or messages
Zero training on your data. Your business data is never used to train, fine-tune, or improve any AI model — public or private. This is a core product commitment, built into how AskCipher works — not a policy that can be toggled off.

Security questions?

Talk to our security team.

Enterprise evaluations often require a detailed security review. We're happy to share our trust documentation, data flow diagrams, and answer questions from your security team directly.

Contact Security Team Technical Docs