FIG. 1 - SECURITY Tenant boundary / no training / erasure roadmap
Answer-first security posture

Trust starts with scoped memory.

Security in Answer Engine starts with tenant boundaries, not enterprise theater. Each memory item, tag, blob, and answer path is scoped to the tenant that owns it; customer data is not used for training by default; and erasure work is labeled until crypto-shred proof ships.

CLAIM STATUS
Now: tenant isolation, no-training default
Now: tenant-scoped deletion controls
Next: crypto-shred erasure proof
Next: SOC 2, SSO/SAML
Available now Hard tenant isolation tested in issue 527No training on your data by defaultTenant-scoped deletion controls
Shipping next Crypto-shred erasure proof SOC 2 SSO/SAML
Fig. 2 available now vs roadmap
FIG. 2

Trust facts

These are the security facts evaluators should inspect before adopting an agent memory layer. Shipped controls are plain; future compliance and erasure proof stay visibly chipped.

Isolation

Tenant boundaries are the security primitive.

Content, tags, blobs, API keys, library membership, and answer retrieval stay scoped by tenant. The security page leads with that boundary because memory becomes sensitive as soon as agents can reuse it.

GROUNDING: issue 527
Training

Customer data is not training material by default.

The managed service posture is simple: customer memory is used to answer that customer's requests, not to train foundation models. Any future opt-in learning surface must be explicit.

DEFAULT: no training
Erasure Roadmap

Deletion exists; crypto-shred proof is still roadmap.

Tenant-scoped delete paths exist today. The stronger right-to-erasure claim - purge embeddings, distilled memory, and crypto-shred proof - stays labeled until the A.5 erasure work ships.

NEXT: crypto-shred
Fig. 3 compliance / erasure proof
FIG. 3

Roadmap claims stay labeled

SOC 2, SSO/SAML, and crypto-shred right-to-erasure proof are important trust work. They are not represented as done until the product and evidence exist.

SOC 2

Certification is a roadmap compliance package, not a held audit status.

SSO/SAML

Enterprise identity controls are planned and stay separate from current API-key authentication.

Crypto-shred erasure proof

The marketing claim unlocks only after purge coverage for rows, embeddings, and distilled memory is implemented and verified.

Fig. 4 FAQPage schema / crawlable answers
FIG. 4

FAQ

Security answers are rendered as static HTML and mirrored into FAQPage JSON-LD for crawlers and answer engines.

Does Answer Engine isolate one tenant's memory from another?

Yes. Tenant isolation is an available-now claim, grounded in issue 527 and reflected across tenant-scoped content, tags, blobs, keys, libraries, and retrieval paths.

Does Answer Engine train on customer data?

No. The default posture is no training on your data. Customer memory is used to answer scoped customer requests, not to train foundation models.

Is crypto-shred right-to-erasure shipped?

Not yet. Tenant-scoped deletion controls exist, but the stronger crypto-shred right-to-erasure proof remains roadmap-labeled until the A.5 product work ships.

Does Answer Engine have SOC 2 or SSO today?

No. SOC 2 and SSO/SAML are roadmap items and are labeled as shipping next, not represented as available-now compliance claims.

FIG. 5 - VERIFY

Use the trust hub before you install.

The trust hub links the security posture, open-source split, and legal surfaces without turning roadmap compliance into shipped claims.

Isolation: tenant scoped
Training: no data training by default
Erasure: deletion now, crypto-shred next
Compliance: SOC 2 and SSO roadmap