Security & Trust
AskCipher never exceeds
what you already permit.
Every action AskCipher takes is bound by the same role-based access controls as the user who initiated it. No elevated privileges. No hidden access. No exceptions.
Core Principles
Six things we never compromise on.
The security architecture of AskCipher is built on principles that can't be overridden by configuration, user preference, or business need.
Inherited permissions only
AskCipher acts using the exact permissions of the authenticated user. It cannot access records the user themselves cannot access.
Zero model training
Your business data — customer records, financial data, employee information — is never used to train any AI model, public or private.
Full audit trails
Every API call, every action, every user command is logged as metadata — timestamp, identity, and outcome, never the contents. Administrators can review exactly what happened and when.
Customer-controlled data retention
Data is retrieved and retained based on your administrators' configuration and permissions. Your organization's rules decide what is kept and for how long.
OAuth-only connections
AskCipher never stores API keys or passwords. All app connections use OAuth authorization flows managed by each application's own identity provider.
Zero cross-tenant data sharing
Each organization's data and context is fully isolated. There is no shared memory or any mechanism by which data from one organization can reach another.
Live Audit Log
Compliance
Meeting enterprise standards.
We build toward enterprise compliance requirements from the foundation, not as an afterthought.
CASA
Certified under the Cloud Application Security Assessment framework, with additional certifications in progress.
Data Privacy
AskCipher's data-minimization architecture is designed to align with data privacy regulations including GDPR. Data processing agreements are available for EU customers.
Data Retention
Retention is governed by your organization's configuration. Business data can be discarded immediately once a task completes.
RBAC Inheritance
All actions are scoped to the requesting user's existing permissions.
Your Data
We use the minimum.
You control what's kept.
When AskCipher runs a command, it reads only what's needed to complete the task — and retains only what your organization's rules allow.
What happens when AskCipher runs
Scoped API read
AskCipher calls your application's API using your existing OAuth session. It reads only the fields required for the specific task — nothing more.
Immediate discard
Once the task is done, all business data can be discarded immediately based on your organization's configuration.
Metadata-only logging
We log which API was called, by whom, and when — but never the contents of the response. Your audit trail is complete without ever exposing the underlying data.
What AskCipher never stores
Regardless of the command, the following categories of data are never persisted, cached, or transmitted outside your execution context — beyond what your organization's retention rules explicitly allow:
- CRM records, contacts, and deal data
- Financial data, invoices, and transactions
- Personally identifiable information (PII)
- Passwords or API keys
- Internal communications or messages
Security questions?
Talk to our security team.
Enterprise evaluations often require a detailed security review. We're happy to share our trust documentation, data flow diagrams, and answer questions from your security team directly.