Security at Partite.ai
Last Updated: [Month Day, Year]
Questions or reports: security@partite.ai (PGP available on request)
Our Security Principles
- Customer-first: You own your content. We process it only to provide the Services to you—we never train models on your content.
- Defense-in-depth: Multiple layers of controls across people, process, and technology.
- Least privilege by default: Access is narrow, time-bound, and audited.
- Privacy by design: We minimize data collection and analyze only aggregate/de-identified telemetry for product reliability and performance.
- Transparency: Clear documentation, reasonable disclosures, and prompt incident communication.
Data Residency & Architecture
- Hosting: Data is stored and processed in the United States only.
- Isolation: Production systems are segmented in dedicated VPCs with strict network policies and security groups.
- Service boundaries: User Content is logically separated by tenant/workspace. Administrative tools operate on metadata only unless elevated access is explicitly granted for support.
Data Ownership & Usage
- You own your content.
- No training on your content: We do not use your prompts, files, datasets, or outputs to train or fine-tune foundation or generalized models.
- Aggregate telemetry only: We analyze aggregate or de-identified operational metrics (e.g., latency, error rates, feature usage counts) to improve reliability — never User Content.
Encryption
- In transit: TLS 1.2+ with modern cipher suites; HSTS enforced on web endpoints.
- At rest: Platform-managed encryption for databases, object storage, and backups.
- Key management: Keys are managed by our cloud KMS; rotation follows provider best practices and internal schedules.
Identity & Access Management
- MFA/SSO: MFA is enforced for administrative accounts; SSO via Google and Github is available for all accounts. SAML/OIDC available for enterprise workspaces.
- Least privilege: Role-based access control (RBAC) with just-in-time elevation for break-glass support; auto-expiry on elevated roles.
- Secrets management: Application secrets stored in a dedicated secrets manager; no secrets in code or CI logs.
- Session security: Short-lived tokens, secure cookies, device-bound refresh where supported.
Vulnerability & Patch Management
- Cadence: Critical patches prioritized immediately; high severity on expedited timelines; regular maintenance windows for others.
- Testing: Canary deployments and automated smoke tests validate security updates.
Incident Response
- Process: Identify → Contain → Eradicate → Recover → Post-mortem (with corrective actions).
- Communication: If an incident materially affects your data or availability, we will notify admins without undue delay via registered email and in-product notices.
- Evidence handling: Chain-of-custody procedures for forensic artifacts; time-synced logs retained per policy.
Business Continuity & Disaster Recovery
- Backups: Encrypted backups taken regularly and stored independently of primary systems.
- Restores: Periodic recovery drills validate integrity and RTO/RPO objectives.
- Availability: Multi-AZ architecture for critical services; auto-scaling and health-based failover.
Data Retention & Deletion
- Retention: User Content is retained to operate the Services and per your workspace settings/contractual needs.
- Deletion: Upon account or workspace deletion, active data is queued for removal; backups and logs are purged on a rolling schedule per retention policy.
Subprocessors & Third Parties
- Scope-limited: We use vetted infrastructure, email, logging, and (where applicable) model/runtime partners to execute your requests.
- No training on your content: Contracts prohibit training on User Content processed on our behalf.
- Review: Security reviews and DPAs (where applicable) are maintained with subprocessors.
Responsible Disclosure (Vulnerability Reporting)
We welcome reports from the security community.
- Email security@partite.ai with steps to reproduce, affected components, and impact assessment.
- Please avoid data access beyond what’s necessary to demonstrate the issue.
- We’ll acknowledge within 72 hours, provide a tracking ID, and keep you updated through remediation.
- If you believe you’ve encountered user data, stop testing and contact us immediately.
Contact
- Security & vulnerability reports: security@partite.ai
- General support: support@partite.ai
Ready to Build Your AI Mesh?
Get started with Partite.ai. The fastest path to reliable AI isn't a bigger prompt — it's a better mesh.