Is my data safe and private on CueCrux?

Explainer

Is my data safe and private on CueCrux?

Encrypted, tenant-isolated, and never used to train models

Data security and privacy are foundational concerns for any platform that handles professional research, and CueCrux addresses them with multiple layers of protection.

Encryption protects your data both in transit and at rest. All communication between your browser and CueCrux servers is encrypted using TLS. Data stored on CueCrux infrastructure is encrypted at rest using industry-standard encryption. This means that even if someone gained physical access to the storage hardware, they could not read your data without the encryption keys. Encryption keys are managed through a dedicated vault service with strict access controls.

Tenant isolation ensures your data is completely separated from other users. When you upload private documents or ask questions, that data lives in your own isolated partition. Other users cannot see your queries, your documents, your receipts, or your research history. This isolation is enforced at the infrastructure level, not just the application level, meaning there is no accidental cross-contamination between user accounts even in the event of a software bug.

Your data is never used to train AI models. This is a critical distinction from some other AI platforms that use customer interactions to improve their models. CueCrux does not feed your queries, documents, or research patterns into model training pipelines. Your private information stays private, period. This commitment is essential for users in regulated industries where data handling requirements are strict.

Access controls let you manage who can see what within your organization. For team and enterprise accounts, administrators can set permissions at the workspace, project, and document level. Role-based access control means that a junior analyst can be given read access to research without the ability to modify or delete it. Audit logs track who accessed what and when, providing the accountability trail that compliance requirements demand.

Authentication uses modern security practices. CueCrux supports single sign-on through major identity providers, enabling your organization to enforce its existing authentication policies. Sessions use short-lived tokens and secure cookies to minimize the window of vulnerability. Multi-factor authentication is available for accounts that require an additional layer of security.

For enterprise customers with specific security requirements, CueCrux offers additional controls. Private knowledge planes can be configured with customer-managed encryption keys. Data residency options allow you to specify the geographic region where your data is stored, addressing regulatory requirements around cross-border data transfer. Network-level restrictions can limit access to your CueCrux instance from approved IP ranges only.

The system is designed with a principle of minimal data retention. CueCrux keeps only what is necessary to provide the service. Query logs are retained for your research history and receipt verification but can be purged on request. Deleted documents are actually deleted, not just hidden from view. Data retention policies can be customized for enterprise accounts to match organizational requirements.

CueCrux undergoes regular security assessments and follows secure development practices. The platform is built with security-by-design principles, meaning security considerations are integrated into the architecture rather than bolted on after the fact. Vulnerability management processes ensure that security patches are applied promptly.

For users handling sensitive information such as legal research, medical data, financial analysis, or government work, the combination of encryption, tenant isolation, access controls, and data handling commitments provides a security posture suitable for regulated environments. You can use CueCrux for confidential research with confidence that your data is protected to professional standards.