Tenant boundaries are the security primitive.
Content, tags, blobs, API keys, library membership, and answer retrieval stay scoped by tenant. The security page leads with that boundary because memory becomes sensitive as soon as agents can reuse it.
Security in Answer Engine starts with tenant boundaries, not enterprise theater. Each memory item, tag, blob, and answer path is scoped to the tenant that owns it; customer data is not used for training by default; and erasure work is labeled until crypto-shred proof ships.
These are the security facts evaluators should inspect before adopting an agent memory layer. Shipped controls are plain; future compliance and erasure proof stay visibly chipped.
Content, tags, blobs, API keys, library membership, and answer retrieval stay scoped by tenant. The security page leads with that boundary because memory becomes sensitive as soon as agents can reuse it.
The managed service posture is simple: customer memory is used to answer that customer's requests, not to train foundation models. Any future opt-in learning surface must be explicit.
Tenant-scoped delete paths exist today. The stronger right-to-erasure claim - purge embeddings, distilled memory, and crypto-shred proof - stays labeled until the A.5 erasure work ships.
SOC 2, SSO/SAML, and crypto-shred right-to-erasure proof are important trust work. They are not represented as done until the product and evidence exist.
Certification is a roadmap compliance package, not a held audit status.
Enterprise identity controls are planned and stay separate from current API-key authentication.
The marketing claim unlocks only after purge coverage for rows, embeddings, and distilled memory is implemented and verified.
Security answers are rendered as static HTML and mirrored into FAQPage JSON-LD for crawlers and answer engines.
Yes. Tenant isolation is an available-now claim, grounded in issue 527 and reflected across tenant-scoped content, tags, blobs, keys, libraries, and retrieval paths.
No. The default posture is no training on your data. Customer memory is used to answer scoped customer requests, not to train foundation models.
Not yet. Tenant-scoped deletion controls exist, but the stronger crypto-shred right-to-erasure proof remains roadmap-labeled until the A.5 product work ships.
No. SOC 2 and SSO/SAML are roadmap items and are labeled as shipping next, not represented as available-now compliance claims.
The trust hub links the security posture, open-source split, and legal surfaces without turning roadmap compliance into shipped claims.