Security
Who gets in, what they see, and proof of both
Three questions, three verifiable answers: who is this person, what are they entitled to, what did they do. Your teams sign in with their company identity, see only their scope, and every access leaves a trace.
Identities
Only the right people get in
Your people sign in with the company account they already use, with no new password to remember. Only the domains you have proven are accepted, and the proof is re-checked every day. Someone who leaves the company loses access along with their account.
- Sign-in with your company directory: Microsoft, Google, Okta and others
- Email domains verified, re-checked every day
- Two-factor authentication available
- Sessions and access keys revocable at any time
SSO domains
- exemple.com DNS verified
- filiale-exemple.com DNS verified
- nouveau-domaine.com Proof pending
Rights
Roles, scopes and source rights
Three roles per organization: administrator, agent, user. Each AI agent has its document scope and its tools, each user sees only the agents assigned to them.
- Administrator, agent and user roles
- Document scope and tools per AI agent
- Agents assigned per person or per team
- Source access rights applied at retrieval
Legal and contracts agent
- Assigned to
- Legal department, 12 people
- Sources
- Customer contracts (SharePoint), internal policies
- Tools
- None
- Out of scope
- HR files, financial data
Traceability
The federated access log
Every sign-in, every access granted and every refusal, including from someone unknown to the organization, is recorded in a searchable, filterable access log. With the governance offer, every decision taken on requests is added to the sealed log.
- SSO sign-ins and accesses logged
- Refusals recorded, unknown or out-of-organization person
- Log filterable by person, date and outcome
- Sealed audit log with the governed offer
| Timestamp | Identity | Outcome |
|---|---|---|
| 2026-09-01 08:42 | [email protected] | Access granted |
| 2026-09-01 08:47 | [email protected] | Access granted |
| 2026-09-01 09:03 | [email protected] | Refused, outside organization |
Data
Your data stays yours
Your documents are never used to train a model. Your keys and secrets are encrypted, and on your servers the encryption key is yours. You set the retention period: what must disappear disappears. Hosted in Europe, or on your premises, down to a network with no outbound connection.
- No data used to train models
- Secrets encrypted at rest, exchanges encrypted in transit
- Retention period and purge according to your policy
- Hosted in Europe or on your servers, down to an air-gapped network
- Visitors of your website authenticated by signature
Security questions
- Which identity providers are supported?
- Any OpenID Connect provider: Microsoft Entra ID, Google Workspace, Okta, Keycloak and others. Configuration happens in your organization’s admin, with DNS domain proof.
- What happens if an unknown person tries to sign in through SSO?
- Access is refused and the refusal is recorded in the federated access log, with domain and date. You then decide whether to invite the person.
- Where is data hosted?
- As SaaS, in our infrastructure in Europe. If you install it on your own servers, with you, up to an installation with no outbound connection. See the On-Premise page.
- Who can read the model keys we entrust?
- Nobody in clear text: they are encrypted at rest and decrypted only at the moment of the provider call. On your servers, the encryption key is yours.
Want to see GuardWeaver at work in your company?
A thirty-minute demo with our team, on your own use cases: your rules, your tools, your teams. Or a free 7-day trial account.