Secure AI
Security
What is encrypted, and who can see what.
Three things to know. The AI company never learns who you are. Nothing you write is used to train AI. And everything you save is stored encrypted. Below is exactly who can see what.
Choosing Secure AI for a team? Start here. Privacy explains why it works this way, the policy is the legal text, and sub-processors lists the companies we work with.
Signing in
You sign in with Google, Apple or Microsoft, so we never see your password and there are no passwords here to steal. Your account can only open its own chats and notes, and fake apps pretending to be ours are turned away.
What happens to a message
Your message comes to us first, never straight to the AI company. We swap your name and private details for stand-ins and ask the question for you, so the AI gets the question and nothing about who asked it. When the answer comes back, your real details go back in before you see it.
Your chats, notes, reminders, projects and memories are stored encrypted. A few small labels are not, so the app can sort and remind you: due dates, which list something is on, whether it is done, and a project’s emoji.
We keep the encryption key and share it with your signed-in devices. That is how a chat you start on your phone opens on your laptop. It also means we could open your data ourselves, and we say so plainly in the list below.
What we can see
This list shows what we could read, not what we do read. We publish it because anything a company can open, a court can ask for. You should know where that line is.
Training
Nothing you type is used to train AI, ours or anyone else's. It is in our contract with every AI company we use, so there is no setting to turn off. It is always off.
Found a hole? Tell us
If you find a security problem in our apps or website, please tell us first. Email company@secureai.one with enough detail for us to see it too. The same address is at /.well-known/security.txt.
We will reply within 3 working days and share our plan within 10. We will never take legal action against anyone who reports a real problem honestly, stays in their own account, and gives us time to fix it. We can't pay rewards yet, but we will thank you by name if you like.
Please stay out of other people's accounts, and don't overload the service for everyone else.
How this compares
Secure AI next to a typical AI account. The right-hand column shows the usual setup, not any one company, since it varies by provider and plan.
| Question | Secure AI | Typical AI vendor |
|---|---|---|
| Does the AI provider know which company is asking? | No — identity is stripped before the request leaves | Yes — the account identifies the customer |
| Who can read a conversation later? | Your devices — we hold ciphertext | The vendor, depending on its policies |
| Is our data used for training? | No — on every plan | Usually off on business tiers |
| How many vendor contracts for frontier models? | One | One per provider |
| Can we reclaim a seat when someone leaves? | Yes — per person | Usually yes |
| SAML / SSO? | Not yet — talk to us about your timeline | Generally available on enterprise tiers |
The questions worth asking
Straight answers about privacy, security and control.
What can the AI provider actually see?
Only the request after identifying information has been replaced. They don’t see your company, your people, or the original values.
Can we verify the redaction rather than trust it?
Today, partly. The redaction runs inside an AWS Nitro Enclave that can provide cryptographic attestation. Independent reproducible builds and automatic verification are not yet available. We’re working on both.
What can Secure AI see?
Your conversations are encrypted to your devices. We see billing information and request volume — not the contents of your conversations.
Can an admin read what their team writes?
No. Personal chats and notes belong to the person who created them. Shared work belongs to the team.
What happens when somebody leaves?
Their seat is revoked. Work they shared with the team remains available to the team; personal work remains private.
Do you rotate the team key when somebody is removed?
Not yet. Removing a member prevents future access, but does not revoke anything they previously decrypted. Key rotation is on our roadmap.
Do you support SAML or SCIM?
Not yet. Sign-in uses Google or Apple, and seats are managed in Secure AI.
Do you have SOC 2 or a DPA?
Our DPA is available at secureai.one/dpa. We do not currently have SOC 2.
Can we pay by invoice?
Yes. Invoice billing is available on request and is standard above 500 seats.
What if redaction misses something?
Redaction is one layer of protection, not the whole system. Unusual identifiers can sometimes pass through, which is why Secure AI uses multiple layers rather than relying on redaction alone.
Independent audit
An outside security audit is still ahead of us. When it is done, the report will be linked here. Vision shows what is built today and what is coming next.
Questions about anything above? Email company@secureai.one.