Security at Partite.ai

Last Updated: [Month Day, Year]

Questions or reports: security@partite.ai (PGP available on request)

Our Security Principles

  • Customer-first: You own your content. We process it only to provide the Services to you—we never train models on your content.
  • Defense-in-depth: Multiple layers of controls across people, process, and technology.
  • Least privilege by default: Access is narrow, time-bound, and audited.
  • Privacy by design: We minimize data collection and analyze only aggregate/de-identified telemetry for product reliability and performance.
  • Transparency: Clear documentation, reasonable disclosures, and prompt incident communication.

Data Residency & Architecture

  • Hosting: Data is stored and processed in the United States only.
  • Isolation: Production systems are segmented in dedicated VPCs with strict network policies and security groups.
  • Service boundaries: User Content is logically separated by tenant/workspace. Administrative tools operate on metadata only unless elevated access is explicitly granted for support.

Data Ownership & Usage

  • You own your content.
  • No training on your content: We do not use your prompts, files, datasets, or outputs to train or fine-tune foundation or generalized models.
  • Aggregate telemetry only: We analyze aggregate or de-identified operational metrics (e.g., latency, error rates, feature usage counts) to improve reliability — never User Content.

Encryption

  • In transit: TLS 1.2+ with modern cipher suites; HSTS enforced on web endpoints.
  • At rest: Platform-managed encryption for databases, object storage, and backups.
  • Key management: Keys are managed by our cloud KMS; rotation follows provider best practices and internal schedules.

Identity & Access Management

  • MFA/SSO: MFA is enforced for administrative accounts; SSO via Google and Github is available for all accounts. SAML/OIDC available for enterprise workspaces.
  • Least privilege: Role-based access control (RBAC) with just-in-time elevation for break-glass support; auto-expiry on elevated roles.
  • Secrets management: Application secrets stored in a dedicated secrets manager; no secrets in code or CI logs.
  • Session security: Short-lived tokens, secure cookies, device-bound refresh where supported.

Vulnerability & Patch Management

  • Cadence: Critical patches prioritized immediately; high severity on expedited timelines; regular maintenance windows for others.
  • Testing: Canary deployments and automated smoke tests validate security updates.

Incident Response

  • Process: Identify → Contain → Eradicate → Recover → Post-mortem (with corrective actions).
  • Communication: If an incident materially affects your data or availability, we will notify admins without undue delay via registered email and in-product notices.
  • Evidence handling: Chain-of-custody procedures for forensic artifacts; time-synced logs retained per policy.

Business Continuity & Disaster Recovery

  • Backups: Encrypted backups taken regularly and stored independently of primary systems.
  • Restores: Periodic recovery drills validate integrity and RTO/RPO objectives.
  • Availability: Multi-AZ architecture for critical services; auto-scaling and health-based failover.

Data Retention & Deletion

  • Retention: User Content is retained to operate the Services and per your workspace settings/contractual needs.
  • Deletion: Upon account or workspace deletion, active data is queued for removal; backups and logs are purged on a rolling schedule per retention policy.

Subprocessors & Third Parties

  • Scope-limited: We use vetted infrastructure, email, logging, and (where applicable) model/runtime partners to execute your requests.
  • No training on your content: Contracts prohibit training on User Content processed on our behalf.
  • Review: Security reviews and DPAs (where applicable) are maintained with subprocessors.

Responsible Disclosure (Vulnerability Reporting)

We welcome reports from the security community.

  • Email security@partite.ai with steps to reproduce, affected components, and impact assessment.
  • Please avoid data access beyond what’s necessary to demonstrate the issue.
  • We’ll acknowledge within 72 hours, provide a tracking ID, and keep you updated through remediation.
  • If you believe you’ve encountered user data, stop testing and contact us immediately.

Contact


Ready to Build Your AI Mesh?

Get started with Partite.ai. The fastest path to reliable AI isn't a bigger prompt — it's a better mesh.