Security and trust
Enterprise context, governed at every step.
Percidian gives each AI system only the context the requesting user or agent is authorized to use. Identity, source permissions, customer boundaries, and traceability are part of every request—not controls added after the answer is generated. Every request passes five checks—who is asking, what they may see, what the task needs, which evidence supports it, where it may go—before any context moves, and every decision is recorded.
Source-native permissions enforced · Customer data never trains third-party models · Customer-controlled deployment
“What are our obligations under the Northwind agreement?”
- who
- Priya Raman · Associate
- sources
- 3 permitted
- context
- scoped to the task
- evidence
- every fact linked to source
- destination
- Microsoft Copilot · approved
- logged
- 09:42:07 · reviewable
Reviewable by security and compliance from one control point.
Illustrative example
- AES-256 at rest
- TLS 1.2+ in transit
- SOC 2 ready
- No third-party model training
Permissions determine the context
Security is not a wrapper around the answer. It determines the answer.
Two people can ask the same question and receive different context because their roles, source access, matter or deal access, and organizational policies are different.
Percidian connects enterprise identities with permissions from the systems of record. Restrictions remain attached to the information as it moves into AI. Explicit restrictions prevail, and unresolved identity or permission data does not result in sensitive context being returned.
- Who is asking?
- What are they permitted to know?
- What does the task require?
- Which sources support the response?
Permission-aware retrieval begins before enterprise information is assembled.
The request path
One request, five checks, one record.
What happens between a request and its answer—what each stage confirms, and what it excludes.
Priya Raman · Associate“What are our obligations under the Northwind agreement?”
Stage 01 of 06
Identity resolved
Who is asking is settled first, against your identity provider — not inferred from the prompt.
Confirms
- Priya Raman · signed in through Okta
- Associate on the Northwind matter team
- Purpose: work on the Northwind matter
Kept out
An identity that cannot be resolved receives no sensitive context. The request stops here.
- who
- Priya Raman · Associate
- sources
- —
- context
- —
- evidence
- —
- destination
- —
- logged
- —
Illustrative example
Controls
What holds, whatever the request.
The boundary the request path runs inside—how data is protected, separated, scoped, retained, routed, and hosted.
- Identity and permissionsSource-native permissions enforced on every request. Connecting a system grants no one new access.Per request
- EncryptionProtected in transit and at rest; customer-controlled keys where the deployment requires them.TLS 1.2+ · AES-256
- Tenant isolationSeparate context, policies, encryption boundaries, and access paths per customer—never used for another customer’s answers.Per customer
- Scoped connectionsEach connector is limited to approved sources, workspaces, users, sites, mailboxes, matters, or repositories.Per connector
- Retention and deletionSource deletion and retention requirements propagate to derived context; logging level and retention are set per deployment.Follows the source
- Model routingApproved destinations only, through customer endpoints or customer-managed credentials. Customer data never trains third-party models.No third-party training
- DeploymentPercidian-managed, customer-controlled cloud, or customer-selected models—the same product, a different boundary. Explore deployment optionsManaged · Your cloud
Security FAQ
The questions a security review begins with.
Answered in brief here; the current architecture, control, deployment, data-flow, and assurance materials are in the Trust Center.
- Can Percidian bypass permissions in a connected source?
- No. Percidian is designed to preserve and enforce source and enterprise access rules. A user or agent does not gain access merely because information has been connected to ACE.
- What happens when an identity or permission cannot be verified?
- No sensitive context is returned when the applicable identity or access decision cannot be established.
- Can we control which models receive our information?
- Yes. Model routing follows customer policy, including approved destinations, customer endpoints, and customer-managed credentials.
Trust Center
The materials a security review needs, in one place.
Architecture, control, deployment, data-flow, and assurance materials are published at trust.percidian.com. Request them there, or schedule a security review with our team.
Governed context, delivered.
Every piece of context is identity-bound, permission-checked, and evidence-backed. Every answer can show its record.
- AES-256
- TLS 1.2+
- SOC 2 ready
- No third-party training
Report a potential security issue. If you believe you have identified a vulnerability, read the disclosure policy and send us the report — it sets out scope, safe harbor, and what you can expect back, and omit customer data, credentials, or other sensitive material from the initial submission; Percidian will establish a secure channel for supporting information.
Bring your business into every AI decision
Give every approved AI system the context to do its best work.
Connect the knowledge your organization already has. Preserve what it learns. Apply the permissions it already trusts. Make that understanding available wherever people and agents work.