Ostrel runs single tenant, holds SOC 2 Type II and ISO 27001, and is GDPR compliant. Content is encrypted at rest with AES 256 and in transit over TLS 1.3. Access is scoped per person, enterprise accounts can sign in through SAML SSO, and connected sources keep the permissions they already carried.
Calendars, shared drives, ticket trackers, wikis and any warehouse that speaks SQL. Anything else can be wired up through the connector API in an afternoon.
Yes, when a workspace admin turns browsing on. Fetched pages are cached for six hours, cited inline, and never written back into your private index.
Text documents, slide decks, spreadsheets, PDFs up to 400 pages, images with readable type, and audio or video that we transcribe on ingest.
In an isolated tenant in the region you pick at signup, with hourly snapshots held for 35 days. Deleting a source removes its embeddings within the same day.
They are inherited, not copied. Every answer is assembled against the reader's own access at the moment they ask, so a revoked file stops being quoted immediately.
A mix of hosted frontier models and two we run ourselves, chosen per task. Every vendor contract carries a zero-retention, no-training clause, and the full roster is listed in the trust centre.
Thirty-one at production quality, and roughly ninety more in a usable but unsupported state. Ask in one language about a source written in another and it will answer in yours.