Security
Published statementOn this website
- Every response carries a content security policy that forbids other sites from framing this one, HTTP Strict Transport Security, and headers that stop content-type sniffing and limit what the referrer and the browser expose.
In client engagements
- Designed for client-controlled data environments, deployed into client cloud, private VPC or hybrid estates.
- Least privilege applied to systems and knowledge sources, with enterprise identity integration where required.