Security

Security at CollectivIQ.

Access, untrusted content, logging and your data.

Identity and access

Sign-in belongs to your company. Connections belong to people.

Single sign-on

Company workspaces sign in through your identity provider over OpenID Connect. Admins configure it themselves. Client secrets are stored encrypted.

User provisioning

SCIM 2.0 provisioning creates, updates and deactivates users from your directory. The token is shown once and can be revoked.

Authorized domains

Company workspaces restrict membership to email domains your admins have authorized.

Your sign-in, your permissions

Business systems connect through your own account with OAuth. CollectivIQ sees what you can see. Nothing else.

Scoped access

Each connection asks for the scopes its job needs. Scopes are listed on the Connections page and can be revoked there.

Workspaces are separate

Personal and company workspaces are partitioned in the data layer. A query in one workspace cannot return data from another.

Role-based knowledge

Shared company knowledge carries the confidentiality of where it was learned. Without the role, it is not shown, summarized or referenced.

Untrusted content

Web pages, documents and inbound email are treated as untrusted.

Web access modes

Strict, Balanced and Open control which sites can be read and whether links are followed. You choose the mode.

Prompt injection

External content is marked untrusted before a model sees it. Instructions inside a page, file or email cannot grant permissions, change recipients or send anything.

Isolated builds

Apps are built in a sandbox separate from the API, with its own network path and no access to your data.

Logging and audit

Actions are recorded.

Audit trail

Actions taken on your behalf, connector calls, API key use, workspace changes and staff actions each write to an audit log.

Readable history

Work done for you is shown in plain language with the tool calls that produced it.

Staff access is logged

Internal support tooling records every record viewed and every action taken by our team.

Data handling

What we store, how it is protected, and who can reach it.

Encryption in transit

All traffic between browsers, our services and third parties uses TLS. Internal service traffic stays inside a private network.

Encryption at rest

Databases, object storage and backups are encrypted at rest with keys managed in AWS Key Management Service. Databases are not reachable from the public internet, and storage blocks public access.

Access to customer data

Production data is not available to staff as a matter of course. Access is limited to two purposes: customer support you have asked for, and product improvement on de-identified data. Support access runs through internal tooling that records every record viewed and every action taken.

Secrets and credentials

Provider keys and connection credentials are held in AWS Secrets Manager and injected at runtime. Connection secrets are encrypted before they are stored. Nothing is kept in code, images or configuration files.

Backups and recovery

Databases take automated backups and can be restored to a point in time. Backups carry the same encryption as the source.

Deletion

Deleting a workspace removes its conversations, files, connections and API keys. Provider-side copies follow the provider retention terms below.

Model providers

Every model runs through its provider's commercial API, under enterprise terms, not consumer ones.

No training on your data

Inputs and outputs sent to model providers are not used to train or improve their models. This is a contractual term of the commercial APIs we use, not a setting.

Limited retention for abuse monitoring

Providers may hold API inputs and outputs for a limited period, typically up to 30 days, solely to detect misuse, then delete them. Content a provider's safety systems flag as violating their policy may be kept longer under that provider's terms.

Zero-retention where available

Some providers and models can run under zero data retention agreements, where nothing is stored after the response is returned. Where a model requires the monitoring window instead, that is a property of the model, and you can choose a different one per request.

Provider access

Providers see the prompt and the response for the request in front of them. They do not have access to your workspace, your files or your connected systems.

Hosting

CollectivIQ runs on AWS in the United States. Model providers run in their own infrastructure under their own terms.

Controls

What administrators and users can set. Each one is a setting in the product today.

Workspace administrators

  • Single sign-on over OpenID Connect, with a pre-save reachability test and on/off toggle.
  • SCIM 2.0 provisioning with a view-once token that can be revoked.
  • Authorized email domains, with a preview of which members a change affects.
  • Model tier allow-list: which cost tiers the workspace may use.
  • Workspace API keys, with an audit of their use.
  • Charges and spend per run, per user and per origin, with a spend dashboard.
  • Web security mode for the organization: Strict, Balanced or Open, plus a site allowlist with built-in defaults.
  • External skills allowlist: which sources skills may be installed from.
  • MCP server grants: which servers members may connect, and per-user OAuth for each.
  • Workspace deletion with a summary of what will be removed before it happens.

Every user

  • Reply policy: who may be replied to automatically, by group, with per-person exceptions.
  • Approvals: approve, reject, reject all, or approve always for a recipient.
  • Pause everything: one switch that stops all proactive work.
  • Quiet hours, in your time zone.
  • Trust settings per action type, and a preview of how any tool call is classified.
  • Never-touch rules: mail that no automation may file, move or act on.
  • Incognito for a conversation: nothing said is remembered or used later.
  • Connection gates: per source, whether it may be read in incognito.
  • Sent log: every outbound message, how it went out and who approved it.
  • Self-service audit of your own account's activity.
  • Sharing of apps and skills to named people, each share recorded.
  • Archive a conversation, and permanently delete individual archived messages.

Questions about a specific control?

Write to info@collectiviq.ai.