Secure AI Integration

Customer-controlled AI workspaces for selected encrypted files, private search, summaries, and source-grounded answers.

Private knowledge over selected files

Cipher Nota Secure AI extends encrypted storage into a controlled knowledge layer. Instead of giving an AI system access to an entire account, a customer selects specific files or folders, creates an AI Workspace and grants only the permissions needed for that task.

Unlike conventional AI assistants, Cipher Nota is designed around least-privilege access: the AI does not automatically gain access to the entire account or master encryption keys. Access can be limited by workspace, permission and time, then revoked when it is no longer needed.


Read Whitepaper
Secure AI workspace

How Secure AI access works

  • Customer selects the files and folders that may be used by AI.
  • Cipher Nota creates an AI Workspace with policy, expiry, retention and model controls.
  • A short-lived workload identity retrieves only authorized encrypted objects.
  • Scoped key operations allow only the granted content to be processed in the approved runtime.
  • Documents are parsed, chunked, classified, and embedded into a tenant- and workspace-isolated store.
  • Every query is filtered by tenant, workspace, object permissions, and revocation state before model context is built.
  • Answers return source citations so users can trace results back to authorized files and versions.

Default AI posture

  • Read-only by default.
  • No account-wide indexing by default.
  • No model training on customer content by default.
  • No external model provider unless explicitly selected or policy approved.
  • No delete, share, move or external communication ability unless separately granted.
  • Workspace keys, indexes and cached chunks are destroyed or retired when AI access is revoked.

AI privacy modes

Private Local AI

Selected files are processed on the customer endpoint when device resources allow. This is the highest-privacy mode.

Confidential AI

Secure RAG and inference run inside an attested confidential runtime where supported, with key release tied to workload validation.

Approved External AI

Third-party model use requires explicit customer or enterprise policy approval, provider controls and minimal shared context.

Planned AI capabilities

  • Ask My Files: natural-language questions over selected authorized files.
  • Semantic Search: find concepts, not only exact keywords or filenames.
  • Document Summaries: summaries grounded in storage-native citations.
  • Cross-Document Analysis: compare contracts, reports, policies or versions.
  • Private Knowledge Agent: a persistent read-only agent over one AI Workspace.

The recommended first release is deliberately narrow: read-only search, summaries, comparisons and source-grounded answers. Tool-enabled agents should follow only after policy gateway controls, capability checks and human approval flows are tested.

Design principle

Storage infrastructure stores ciphertext. Cryptographic systems control key authority. Customers control recovery and AI grants. The AI policy plane controls what an agent may retrieve or do. No AI model should independently obtain permission to access or modify customer data.

Secure storage when you need durability. Secure knowledge when you need answers. Customer-controlled cryptographic authority across both.