Skip to content
loqy

CURRENT CONTROLS

Trust center

This page describes controls currently present in the product and infrastructure. It does not turn an intention into a commitment.

Updated · July 16, 2026

Data isolation

Workspace data is protected by RLS and repositories that propagate tenant context. Platform routes are separated from workspace routes.

Conversations are private by default; sharing follows project rights or explicitly added members.

Identity and access

Authentication relies on Supabase Auth. Workspace, project, and Platform access is checked on the server and in the database.

Sensitive operations use dedicated guards. Deleting access request PII requires a request-specific phrase and visible confirmation.

Models, tools, and secrets

Available models and tools are bounded by workspace policies. Tools are not exposed as an implicit global authorization.

BYOK key references are masked in the UI and resolved on the server. Runtime checks the workspace key before an allowed platform fallback.

Files and audit

Documents, citations, generated files, and artifacts remain attached to their conversation or project when the corresponding feature is used.

Sensitive Platform events feed an append-only log. Access request deletion keeps an audit event without requester PII.

Observability and incidents

Availability checks, application logs, and metrics support diagnosis. Public OpenPanel telemetry is limited to PII-free events.

Published limits

No third-party attestation, infrastructure location, or availability duration is published here without dedicated evidence and validation.

Any commitments are defined in separately communicated terms; this page remains descriptive.