curiosity

Developers

Security built in,
not bolted on

Permissions added after the fact leak. Curiosity resolves access once, at query time, against the rules the source systems already hold, and every surface inherits it.

A request through identity and authorization to one record A request passes identity, by single sign on, and authorization, per record, to reach a ticket. A second request is refused at authorization. Both are written to the audit log. 01 · IDENTITY02 · AUTHORIZATIONTCK-8812REQUESTSSO ✓ACL ✓REFUSED03 · AUDIT09:42:11 READ TCK-8812 user 1184 allowed09:42:13 READ CTR-0071 user 1184 refused
Every request: Identity, Authorization, Audit Identity: SSO from your provider, MFA enforced. Authorization: Per record, synced from the source. Audit: Every query, access and download logged. All inside one every request. 01 Identity SSO from your provider, MFA enforced 02 Authorization Per record, synced from the source 03 Audit Every query, access and download logged

Capabilities

Security and governance by design

Enterprise-grade across identity, data and deployment.

Relationship-based permissions

Access depends on the record and how it was reached, not on a folder-level approximation.

Synced from the source

The source system stays authoritative for who can see what.

SSO with enforced MFA

Identity from your provider; no parallel account to forget to deprovision.

Full audit trail

Every query, download and access, including what an agent did on someone’s behalf.

Your infrastructure

On premises or private cloud, with keys you hold.

No training on your data

Records are not used to train models. The model is a component, not a counterparty.

Questions for developers

The things worth asking first

Can a user see something they should not?

Every result is checked against the user's teams and restrictions when the query runs, down to node types and fields. What those restrictions are depends on what your connector syncs from the source.

Where is data processed?

Wherever you deploy. Search, embeddings, entity extraction and OCR run inside Studio, and with a local model nothing goes to an AI provider. Set MSK_DISABLE_TELEMETRY and MSK_DISABLE_CLOUD_ERROR_REPORT to stop usage counts and error reports going to Curiosity. The front end reports product usage to Mixpanel.

Is there an audit export?

Yes. Admins choose which actions are logged, then filter and download the trail. The log files carry a hash chain you can verify from the command line, which also converts them to CSV or JSON for your own retention.

Your data. Your infrastructure.

Security that survives an audit