Security
Know how access works.
Clear account boundaries, explicit project permissions and a record of privileged changes are part of the platform.
Your account, your sessions.
Email sign-in uses a time-limited, single-use link. Google sign-in is available when configured. Signed sessions are held in HttpOnly cookies, and the account security page lets you inspect and revoke sessions.
Research with defined access.
Personal projects belong to your account. Organisation projects check membership and permissions on the server. Revision checks help prevent a colleague’s changes from being silently overwritten.
Separate administration.
Platform operators use a separate sign-in. Privileged changes require recent authentication and record an audit event. An ordinary account or team-owner role does not grant platform administration access.
Evidence you can inspect.
Indexed documents retain version and source context. Cited research identifies exact passages for review. Generated text is still something to assess; a citation alone does not establish a claim’s correctness.
Discuss your requirements.
All regions currently use Disclosure Global. Before bringing confidential material, ask us about the deployment’s hosting, providers, retention and recovery arrangements. These depend on the service configuration.
This page describes implemented controls. It is not a claim of independent security certification, regional data residency or enterprise SSO.
Contact Disclosure