Customer-controlled AI workspaces for selected encrypted files, private search, summaries, and source-grounded answers.
Cipher Nota Secure AI extends encrypted storage into a controlled knowledge layer. Instead of giving an AI system access to an entire account, a customer selects specific files or folders, creates an AI Workspace and grants only the permissions needed for that task.
Unlike conventional AI assistants, Cipher Nota is designed around least-privilege access: the AI does not automatically gain access to the entire account or master encryption keys. Access can be limited by workspace, permission and time, then revoked when it is no longer needed.
Selected files are processed on the customer endpoint when device resources allow. This is the highest-privacy mode.
Secure RAG and inference run inside an attested confidential runtime where supported, with key release tied to workload validation.
Third-party model use requires explicit customer or enterprise policy approval, provider controls and minimal shared context.
The recommended first release is deliberately narrow: read-only search, summaries, comparisons and source-grounded answers. Tool-enabled agents should follow only after policy gateway controls, capability checks and human approval flows are tested.
Storage infrastructure stores ciphertext. Cryptographic systems control key authority. Customers control recovery and AI grants. The AI policy plane controls what an agent may retrieve or do. No AI model should independently obtain permission to access or modify customer data.
Secure storage when you need durability. Secure knowledge when you need answers. Customer-controlled cryptographic authority across both.