Security & trust
Private by default. Answerable by design.
Your knowledge belongs to you. What you add is visible only to you and the people you explicitly share it with, and the system enforces that per viewer on every surface, including the assistant, which sees only what you can see.
Architecture
Trust is a property of the substrate.
Access control, provenance, and privacy are how Spectrea is built, not features added afterwards.
Per-viewer truth
What you see is synthesized from exactly the claims you can access. Two people can ask the same question and get different answers, each honest to what that person is allowed to know. Nothing leaks from views you cannot see.
Provenance on every answer
Every answer, claim, and connection can be followed back to its source. Every action the assistant takes is recorded, attributed, and reviewable. You can always ask why and get an answer.
Enforced in the database
Access rules live in the database as row-level security, not in application code alone. The assistant queries under the same enforcement as the person asking, so there is no privileged path around your permissions.
AI with review
The assistant suggests, surfaces, and drafts. It never decides for you, and nothing it proposes lands in your graph until you accept it. On the managed path, your data is not used to train foundation models: a contract we are formalizing, with independent attestation as a stated target.
Yours to keep
Your knowledge belongs to you. Audit-trail export ships today; full-fidelity export of your workspace, structure, data, and provenance included, is a first-class guarantee we are building toward launch. Deleting your account removes your data from live systems within 30 days.
Keys and deployment
Bringing your own model keys and endpoints is part of the design, with key material held in a managed secrets vault. Deployment options widen by tier, from managed cloud toward single-tenant and air-gapped: staged targets, stated as such.
Compliance
A program, not a badge.
Formal attestations, SOC 2, ISO 27001, and ISO 42001-class AI governance among them, are staged targets on our roadmap and we state them as such. We will not print a certification we have not attained, and we will not claim zero-knowledge properties the architecture does not have.
Spectrea is operated by Matchwise Pte. Ltd., incorporated in Singapore, and handles personal data under the PDPA. Ask for the current program status and we will show you exactly where it stands.
Put us through review.
Security questionnaires, architecture walkthroughs, and awkward questions are welcome. That is what the walkthrough is for.