Product reference

Security and Privacy

How Pantasso handles workspace isolation, data access, support redaction, and operator control.

Status: Live · Updated 2026-07-12

Security and Privacy

Pantasso is designed for companies that need to control how their data is organized, accessed, and shared. This document covers how Pantasso handles workspace isolation, data access, support redaction, and operator control.

Workspace isolation

Each workspace is isolated from every other workspace. There is no cross-workspace data sharing, search, or access. Workspace data is not used to train models or improve the platform.

Source access

Sources are strictly opt-in:

  • No source is connected unless the workspace owner explicitly approves it.
  • Each source connection specifies exactly what Pantasso can access (specific channels, folders, documents).
  • Source access can be revoked at any time.
  • Disconnecting a source stops all future syncs and can archive imported objects.

Agent boundaries

Agent profiles enforce access boundaries:

  • Each profile has a defined scope that limits what workspace objects the assistant can access.
  • Profiles do not grant access to sources that the workspace owner has not connected.
  • All agent queries are logged with the profile identity, query content, and response type.

Support redaction

When you request support, Pantasso generates a support packet that is redacted before transmission:

  • No raw message content from workspace sources.
  • No credentials, tokens, or API keys.
  • Health status, configuration summary, and error context only.

The workspace owner can review the support packet before sending.

Operator control

Workspace owners have full control over:

  • What is connected: Which sources are approved and what content is imported.
  • Who has access: Which agent profiles exist and what scope they have.
  • What is exported: Support packets, backup exports, and any external data sharing.
  • What is deleted: Sources, objects, profiles, and workspace data can be removed.

Activity logging

Pantasso maintains an activity log that records:

  • Source connections and disconnections.
  • Import and sync events.
  • Cited queries and their results.
  • Agent profile creation, modification, and usage.
  • Support packet generation.

The activity log is available to workspace owners from the control plane.

Data retention

Workspace data is retained as long as the workspace is active. Workspace owners can:

  • Delete individual objects or sources.
  • Export workspace data for migration.
  • Delete the entire workspace and all associated data.

Enterprise organizations can configure custom data retention policies.