Our approach to security

Protected, without being watched.

Day to day, admins see only usage and cost. Conversations belong to the person and whoever they shared them with.

See for business
Protected, without being watched.
Audit

Traceable when it matters.

Audit events are recorded, queryable via API, and exportable. Legal Hold is available to discuss under Enterprise.

See audit logs
Traceable when it matters.
Security Filter

Keep company information from leaving.

A Security Filter that detects and masks sensitive data before sending, then restores it in the response, comes standard.

See the feature
Keep company information from leaving.

Protect without reading.

Rolling out AI across a team creates two seemingly opposite jobs for admins: respecting each person's privacy, and protecting the company's information. Prompt Flow Studio is built so both can coexist, as a standard part of a multi-AI workspace.

Questions? Contact us.

Who this page is for

IT teams

Checking how authentication and access control work.

Legal & compliance

Checking what's captured in audit logs and how to retrieve it.

Security reviewers

Checking how data is stored and how runaway costs are prevented.

Protect by not looking — not by watching everything.

Day to day, we don't look.

Conversations and generated artifacts belong to the people in them, and whoever they're shared with. What admins see day to day is team usage and cost — PFC consumption and storage usage. Members control who a thread is shared with, through access control lists (ACLs).

When it matters, you can trace it.

Every action is recorded as an audit event: who, when, what. Query it via API, export it as CSV/JSONL with a SHA-256 checksum, or browse it in the admin viewing UI, any time. Legal holds for litigation or investigations, and long-term retention, are available to discuss through the Enterprise program.

Company information doesn't leave.

Security Filter detects and masks sensitive or personal information before it's sent, then restores it in the response, as a standard capability (Team: detect and warn, Business: auto-mask and restore, Business+: contextual detection and mask-event audit review). Custom detection rules, bring-your-own detection dictionaries, and an org-wide enforced policy are available to discuss through Enterprise. Model catalog governance, letting admins control which AI models the organization can use, is included as well.

What admins can see / can't see

This reflects day-to-day operation. Shared threads and legal processes (such as Legal Hold, through the Enterprise program) change what's visible.

項目VisibleNot visible (day to day)
Team usage & PFC consumption
Contracted seat count
Audit event metadata (who, when, what)
The content of conversations and artifacts

Governance only works because it's multi-AI.

When employees sign up for ChatGPT, Claude, and others individually, usage logs and access controls end up scattered across services the company can't see.

Bringing multiple AI providers into a single workspace puts authentication, permissions, and audit logs in one place — which is what makes cross-cutting governance possible in the first place.

What powers this approach

Onion SSO authentication

Login runs through Onion SSO.

Thread-sharing ACLs

Thread sharing is governed by an access control list.

Audit event logging & query API

Actions are recorded as audit events and available through a query API.

Artifacts & knowledge stored in S3

Generated artifacts and uploaded knowledge documents are stored in S3.

Balance guard against runaway cost

Execution stops before your PFC balance runs out, preventing unintended overuse.

What you can discuss through Enterprise

Security Filter comes standard on Team, Business, and Business+ (Team: detect and warn, Business: auto-mask and restore, Business+: contextual detection and mask-event audit review). Custom detection rules, bring-your-own detection dictionaries, and an org-wide enforced policy that individual users can't opt out of are available to discuss through the Enterprise program.

Tamper-evident audit logs (hash chain) come standard on Business and above. Legal holds for litigation or internal investigations, GDPR erasure, and 7-year audit retention (statutory retention, linked to Legal Hold) are available to discuss through the Enterprise program.

Frequently asked questions

Generated artifacts and uploaded knowledge documents are stored in S3.

Start with the free plan and try all four modes.

Start free
Language日本語English