Security
Built for the procurement and legal review.
Identity, data, audit, model governance, and deployment options designed for regulated and risk-aware teams. The kind of answers your security team expects on call one.
Access & identity
- SSO via SAML 2.0 and OpenID Connect
- SCIM provisioning for joiners and leavers
- Role-based access control with custom roles
- Per-source permission inheritance — Deskor never grants more than the source allows
Data security
- AES-256 encryption at rest, TLS 1.3 in flight
- Customer-controlled retention windows
- Data residency in US, EU, or your VPC
- No training on your data — ever — across managed plans
Audit & traceability
- Every prompt, retrieval, and output captured
- Source citations on every answer the platform produces
- Exportable audit log to SIEM via webhook or scheduled drop
- Tamper-evident hashing for regulated workloads
Model governance
- Per-task LLM routing across GPT, Claude, Gemini, open-source
- Cost ceilings per team and per agent, with hard stops
- Policy guardrails that block restricted data classes from prompts
- Human-in-the-loop review thresholds on output confidence
Deployment options
- Workspace: hosted by Deskor, all-inclusive infrastructure
- Workspace Enterprise: private deploy in your AWS, GCP, or Azure VPC
- Unique License: full ownership — your infrastructure, your operators
- Region pinning available for data residency requirements
Compliance
- SOC 2 Type II path on Workspace Enterprise
- GDPR-aligned terms with DPA available
- HIPAA path under negotiation for healthcare engagements
- Vendor security questionnaires answered in days, not weeks
Need a security questionnaire turned around?
We answer in days, not weeks. Send us your standard form and we'll come back with the matrix and the supporting docs.