Glafeli was designed from the ground up with enterprise security. Encryption, permissions inherited from your directory, complete traceability — and your data is never used to train AI models.
Standards & compliance
Not a last-minute configuration. Security architecture is integrated from the product's design up.
All traffic travels encrypted with TLS 1.3. Data at rest is encrypted with AES-256. Encryption keys are customer-managed via KMS — Glafeli never has access to plaintext keys.
Permissions are automatically inherited from Google Workspace, Microsoft Active Directory or your corporate IdP. If a document isn't visible to a user at the source, it's not visible in Glafeli either. No manual configuration required.
The AI models Glafeli uses do not learn from your data. Queries are processed in pure inference mode with zero retention. AI providers operate under zero-data-retention agreements and have signed GDPR-compliant DPAs.
Every query is logged: user, timestamp, question, answer, and cited source. Logs are immutable and exportable. In a regulatory audit, you can prove who accessed what knowledge and when.
Processing and storage can be configured in localized infrastructure in Latin America or Europe. Data does not cross borders without explicit customer consent. Available on Business and Enterprise plans.
Native SSO support via SAML 2.0 and OAuth 2.0. Mandatory MFA for administrators. Integration with Okta, Azure AD, Google Identity and any OIDC-compatible IdP. Configurable session expiration.