Security & trust

Context has boundaries. Keep them.

A useful memory system needs to understand who is asking. Slashh applies permissions during retrieval, before context is used to compose an answer.

The path of a request

  1. 01

    Identify the asker

    Establish the person or scoped agent making the request.

  2. 02

    Check the context

    Evaluate access before passing retrieved content to the model.

  3. 03

    Return the evidence

    Build the answer from permitted sources and preserve citations.

Controls you can inspect

Trust belongs in the details.

Use these as starting points for an evaluation of your sources, identity setup and deployment.

Identity before retrieval

Requests are associated with a person or an agent principal. Access checks determine the context available to that request.

Scoped agents

An agent’s granted scopes narrow what it can do on behalf of its owner. Treat credentials as secrets and grant only the access a workflow needs.

Evidence with the answer

Citations connect an answer to its supporting sources. Historical queries can distinguish what was true from when it became known.

Inspectable access

Permission and audit views help administrators investigate access decisions. Review retention and export requirements for your deployment.

Deployment choices

Self-hosting and model configuration affect where data is processed. Review the complete source-to-model path before connecting sensitive systems.

See the boundary

One question. Context for the person asking.

The interactive home example lets you switch between a team member and a guest. The answer changes with the available evidence.

Permission model / illustrative exampleTry switching roles ↗

Team member

An answer supported by the shared overview and the team’s project conversation.

Permitted team context

Guest

An answer supported by the shared overview available to that guest.

Permitted shared context

Private preview

Clear about where we are.

Evaluate the current deployment against your requirements. A capability description is not a certification.

Is Slashh SOC 2 certified?

No. Evidence exports and control mapping can support a review, but they are not a SOC 2 certification or an independent attestation.

What should we review before a pilot?

Identity provisioning, source permissions, credential handling, model providers, hosting location, retention, deletion and audit-log durability. We will work through the configuration and gaps with you.

Can we assume production audit retention?

No. The preview access-log implementation may use server memory. Confirm durable storage and retention requirements before relying on it for compliance evidence.

Does the preview include SCIM provisioning?

SCIM provisioning is not a published preview commitment. Discuss identity lifecycle and offboarding requirements before starting a deployment.

Your next step

Bring your security questions.

Walk through the permission model and your deployment requirements with us.

Discuss your requirements