Security First. Always.
Curiosity is built to pass enterprise security review. Deployment, encryption, permissions and audit controls are documented below.
Curiosity is built to pass enterprise security review. Deployment, encryption, permissions and audit controls are documented below.
Control
Status
With On-Premise Workspaces, your data always stays in your environment (can be completely air-gapped).
With Cloud Workspaces, data is hosted with providers with industry-recognized certifications (e.g., ISO 27001, SOC 2).
Cloud Workspaces are hosted on Hetzner, a European provider with infrastructure in Europe.
Customer data is separated in isolated tenants.
Deployment and secrets are managed through dedicated secure systems with restricted access.
Hosting environments receive frequent OS and dependency updates.
Control
Status
All communication uses TLS 1.2+ to protect data in transit.
All data stored in Curiosity Workspaces is encrypted using AES-256.
Sensitive tokens and credentials are stored encrypted using secret-management tools.
Customer data is never used to train shared or public AI models.
Control
Status
Authentication integrates with providers like Google, Microsoft, OKTA, Auth0, and SAML2.
Customers using SSO can enforce MFA through their identity provider.
Internal roles follow strict minimal-access principles.
Controls for restricting user access to specific Workspace features.
Only authorized Curiosity personnel can access production systems, and only when required.
Control
Status
Customers can manage permissions for teams, workspaces and user roles.
Permissions can be synced with data sources to avoid duplication and propagate changes.
Permissions are handled at the graph database level, so they reflect across all features.
AI features only use or generate content the user is authorized to access.
Admins can restrict AI models, data sources, and tools access per workspace.
Control
Status
User actions like search, file access, edits and settings changes can be logged.
Workspace admins can monitor exports and file downloads.
Assistant queries, generated outputs, and model interactions can be logged for compliance.
Relevant events can be monitored to detect anomalies or unauthorized access.