Security & trust
Trust through mechanics — not borrowed badges.
Continuum is designed for permission-aware operational knowledge. We describe current safeguards and planned work without inventing certifications.
Principles
- Tenant / organization isolation in the product data model
- Source permissions and least-privilege retrieval intent
- Role-aware access to workspace surfaces
- Source-level traceability for material claims
- Expert-note attribution and review state
- Human approval for consequential actions
- Audit history for sensitive lifecycle events
- Data deletion and retention treated as customer-policy work, not marketing slogans
- Secrets managed via environment configuration — never embedded in the public site
- Model-provider boundaries: deterministic product paths must not require leaking private corpora into uncontrolled training
- Logging boundaries: public analytics avoid free-text PII
Current safeguards
- Session cookies with HMAC integrity checks in middleware
- Membership-scoped workspaces in the application core
- Role checks on action approve/execute paths with deny audit events
- Cross-tenant isolation covered by automated tests in the monorepo
- Public demo uses synthetic fixtures only — no customer uploads on the marketing form
Under development
- Production multi-tenant hosting hardening for app.veldarium.com
- Broader connector permission mapping
- Customer-managed retention policies in production
- Expanded evaluation and monitoring for retrieval quality
Planned
- Enterprise identity integrations beyond the OIDC skeleton
- Formal third-party security review when the product stage justifies it
- Documented subprocessors list for production SaaS
What we do not claim
- SOC 2, ISO 27001, HIPAA, FedRAMP, or equivalent certifications
- Completed formal penetration testing or external audits
- Regulatory compliance for any specific industry regime
- Production security maturity equal to large horizontal platforms
Questions: founders@veldarium.com