Built for information that should remain controlled

Alusia assumes your documents are confidential by default. These are the concrete mechanisms, not slogans.

Architecture

  • Private storage buckets; documents are never publicly addressable.
  • Organization isolation enforced by row-level security in the database - every query, not just the UI.
  • Role-based access control: owner, administrator, member, viewer, with server-side enforcement of every change.
  • Restricted collections are filtered before retrieval; restricted content never enters another user’s answers.
  • All AI requests originate server-side. Browsers never hold AI provider keys and never talk to AI providers directly.
  • Retrieved document text is treated as untrusted data - instructions embedded in documents are never followed.
  • Two-factor authentication (TOTP authenticator apps) with recovery codes; an administrator can require it for all members of the organization, enforced server-side.

Data handling

  • Your documents, extracted text, search indexes and conversations are stored at rest in the EU (Frankfurt, Germany). AI processing (embeddings and answers) on standard plans is performed by OpenAI and may run outside the EU.
  • Your documents and questions are never used to train AI models - ours or our providers’.
  • Document text is sent to the AI provider only to index your documents and answer your questions, under API terms that prohibit training on it; the provider may retain it briefly for abuse monitoring and then deletes it.
  • Full organization export and deletion, including indexed content, on request.
  • Audit events record security-relevant actions with actor and time.

Operational practice

  • Secrets live in server-side secret stores; they are never shipped to browsers or logged.
  • Error monitoring and structured security events across web, API, and processing workers.
  • Support access to customer data is time-limited, read-only by default, and audited.

Certifications

Certifications are listed here only once attained. We publish our current compliance status honestly rather than claiming badges early.

Reporting a vulnerability

Security reports are welcome at security@alusia.net; we acknowledge within two business days.

security@alusia.net