Security and Trust — hosted public beta

Workspace isolation and source-level access control.

Pantasso is a hosted public beta. Start with Files or Obsidian. Slack, Drive, Telegram, and GitHub need a connection. The public beta isolates workspaces, reads only approved sources, and redacts support diagnostics. Default SSO, SLA, and independent restore are scoped during founder-led evaluation.

Key principles

Security built into the platform, not bolted on after.

Every workspace, source connection, and agent interaction follows the same isolation and access-control model. These are not optional add-ons.

Workspace isolation

Every workspace runs in its own logical boundary. Data, configurations, agent profiles, and query history are fully isolated between organizations. There is no shared tenancy surface where one workspace can observe another.

Source-level access control

Each approved source has its own permission scope. In the hosted public beta, owners start with a Files or Obsidian set. Slack, Drive, Telegram, and GitHub need a connection before their channels, folders, chats, or repositories can be read. Nothing is indexed without explicit approval.

Redacted support reports

When a workspace needs help, the support report strips company-specific content before transmission. Pantasso support sees workspace health metrics and configuration state, not the underlying company data.

Data governance

You decide what Pantasso may see. Everything else stays out.

Governance in Pantasso starts with the workspace owner. Sources are approved one at a time, queries are logged, and agents operate within explicit boundaries.

Opt-in sources only

Pantasso never crawls or indexes data that has not been explicitly approved by a workspace owner. Adding a new source requires a deliberate selection, not a bulk import. Excluded channels, folders, and files are named up front and enforced throughout the data lifecycle.

Opt-in sources only

Audit trail for all queries

Every query, retrieval, and agent interaction is logged with the requesting identity, the sources consulted, and the records returned. Workspace owners can review who asked what, when, and which sources contributed to each answer.

Audit trail for all queries

Agent boundary enforcement

AI assistants operate within scoped profiles that define what each agent may read, what it may draft, and when it must defer to a human. Agent profiles do not grant new source access on their own, and boundary violations are logged.

Agent boundary enforcement

Infrastructure

How Pantasso handles deployment, data, and operations.

The platform infrastructure is designed for reliability, auditability, and controlled access at every layer.

Deployment and hosting

The hosted public beta runs on managed infrastructure with encrypted storage at rest and in transit. Controlled release and rollback are scoped during evaluation, not a public-beta default. Infrastructure access is restricted to authorized operators.

Data handling

Ingested data is structured into typed records with full provenance. Source credentials are stored separately from workspace content. Deletion requests remove both the indexed content and its metadata from the workspace.

Backup and recovery

Workspace backup and recovery are scoped during founder-led evaluation. The public beta does not include automated point-in-time recovery or independent restore.

Operational monitoring

Source freshness, ingestion health, retrieval quality, and agent activity are continuously monitored. Workspace owners see a health dashboard; platform operators see system-level metrics without accessing workspace data.

Review your requirements with us.

Tell us about the source you want to evaluate and the access, data, and review requirements your organization needs to address.