---
title: How Vythos is secured
description: Isolation between workspaces, how connector access is stored, what reaches a model, and who can see what inside your own team.
---

<span class="vy-eyebrow">Security and data</span>

# How Vythos is secured

Your rules are among the more sensitive things an agency owns: what you charge,
what you've committed to, what you've agreed with each client. Here's how that
material is kept.

## Workspaces are isolated in the database

Every row Vythos stores carries the workspace it belongs to, and that isolation
is enforced by the database itself rather than by application code remembering
to filter. The account the application connects with cannot bypass it.

The practical meaning: a bug in a query can't return another workspace's
material, because the database will not serve it.

## Inside your workspace

- **Rules are shared, filtered by access.** Each person has a level for each
  category, and a category set to no access is never sent to them — not on
  screen, not to their AI tools. See
  [Your team and their access](/using-vythos/team-and-access).
- **Memory is private to each person.** Your uploads and your connected
  accounts feed your memory only. Nobody else can search it, the workspace
  owner included.
- **Connections are personal.** Each person authorises their own Google, Notion
  or GitHub account, and Vythos reads with exactly that person's access.

## Connector access is encrypted at rest

The tokens that let Vythos read your Drive or Notion are encrypted before they
are stored, with authenticated encryption, and are decrypted only to make a
request on your behalf. They are never written to logs, never returned by the
API, and never shown in the app.

## Sign-in

- Passwords are hashed with bcrypt. Nobody at Vythos can read yours.
- Repeated failed sign-ins for an address are throttled, and the throttle is
  checked before the password, so a refused attempt reveals nothing about
  whether an account exists.
- Password reset is by emailed link.

## What reaches a model

Vythos uses large language models for two things: writing an answer in Ask, and
reading values out of a document when you add a rule. A separate model turns the
text of each document into a search index (embeddings) when it's read in, and
each question into the same form when you search.

- The models run on **Microsoft Azure (Azure OpenAI)**, in the EU: requests are
  processed only in EU member states.
- What's sent is the material needed for that request — for a question, the
  rules and passages relevant to it, your agency's description and client list,
  and the last few turns of your own conversation; the text of the document
  you're adding; or, for indexing, the passages of a document.
- Microsoft's terms are that prompts and answers are not used to train models,
  are not available to OpenAI or any other model provider, and are not available
  to other customers. Vythos does not train anything on your material either.
- Azure runs automated abuse monitoring. Content it flags may be kept for human
  review, stored in the EU and reviewed only by authorised Microsoft staff in the
  European Economic Area.
- The rest of the product — following documents, versioning, permissions,
  checking a draft against values — involves no model at all. Draft checks in
  particular are deterministic: the same draft and the same rules produce the
  same result every time.

## What Vythos stores, and what it doesn't

**Stored:** the text of documents you connect or upload, split into passages
and indexed; your rules and their history; your clients and your agency's
description; your team and their access; each person's Ask conversations,
readable only by them; records of what was handed to which AI tool, so a draft
can be checked against it.

**Not stored:** your files themselves. Vythos reads documents where they live
and keeps the text; it never becomes the place your documents are kept.

## Outside services involved

| Service | What for | What it sees |
|---|---|---|
| Microsoft Azure — Azure OpenAI, EU | Generating answers, reading values from documents, indexing text for search | The text needed for that request; each passage of a document when it's indexed |
| Google, Notion, GitHub | Reading the documents you connect | Only what the account you connected can see, and only what you selected |
| An email provider | Invitations and password-reset links | The address and the message |

## Reporting something

If you think you've found a security problem, email us rather than opening a
public issue, and give us a way to reproduce it. We'll confirm we've received
it and tell you what we're doing about it.

Next: [Your data](/security/your-data).
