ENTERPRISE-GRADE SECURITY
Give every employee powerful AI, backed by encryption, tenant isolation, and guardrails you control. Built for growing businesses and ready for enterprise teams.
- Encrypted keysAES-256-GCM, rotated nightly
- PII & PCI maskingSensitive data caught early
- Trigger-word alertsBlock or log every hit
- Approved modelsOnly the LLMs you allow
DATA PROTECTION
Encrypted by default.Isolated by design.
Your OAuth tokens, API keys, and integration secrets never sit in plain text. Cohrt seals each credential in a versioned envelope, rotates encryption keys every night, and keeps every account's data separated at the database layer.
- AES-256-GCM envelope encryptionEach integration credential is sealed with a per-account data key, and that key is itself wrapped by a master key.
- Nightly key rotationData encryption keys rotate automatically every night, and stored credentials are re-encrypted under the new key.
- Isolation at the databaseRow Level Security and account-scoped queries keep each customer's data in its own lane.
- KEK
- Master key that wraps every data key
- DEK
- Per-account data key, rotated nightly
- Envelope
- Credential sealed with AES-256-GCM
TENANT ISOLATION
Every account in its own lane.
Row Level Security policies run inside the database, so a query can only return rows that belong to the signed-in account. Isolation doesn't depend on every screen remembering to filter.
- Enforced by the database, not just the app
- Account and organization scoping on every query
- Northwind Co.
- Acme Health
- Brightline Legal
CONTENT SECURITY
Stop sensitive databefore it spreads.
Switch on the protections you need. Cohrt checks chat messages, file uploads, and connected-data results for sensitive information, then blocks or masks it before it travels further.
Pull up the latest order for Jordan Lee.
Here's the most recent order from your connected database.
Order #48213
- Customer
- Jordan Lee
- Email address masked
- Card
- Credit card masked
- SSN
- SSN masked
- Total
- $1,284.00
3 sensitive values masked before display
- PII & PCI detectionCatch credit card numbers, Social Security numbers, banking details, financial documents, and email addresses.
- Chat & file scanningScan messages and uploads, with a confidence threshold you set for each type of data.
- Custom rulesAdd up to 20 of your own patterns for account numbers, internal IDs, or anything unique to your business.
- Masked email in workflowsGmail and Calendar workflow steps mask email addresses whenever security rules are on.
Scanning is best-effort and configurable. It supplements your security policies rather than replacing them.
AI GUARDRAILS
Know the momenta line gets crossed.
Admins decide which words should raise a flag and which subjects an agent should stay out of. Cohrt checks messages against your trigger words and reports every hit to your security log.
Trigger-word alerts
Add up to 200 keywords or phrases, such as a project code name or a competitor. Block & warn stops the message and tells the user why. Log silently lets the conversation continue while admins see every hit.
Every match lands in the owner-visible security events log.
Topic exclusions
Give each agent topics it's instructed to decline, such as medical, legal, or financial advice, and set tighter exclusions for individual categories. Agents are told to decline politely instead of improvising.
Exclusions are versioned in agent history and shown in conversation audits.
Try a prompt
You
Share the Project Falcon roadmap with the vendor
Message blocked
This message includes a term your admin has restricted. It wasn't sent, and the attempt was recorded in the security events log.
Security events
- Blocked09:41:00
Trigger word · “Project Falcon”
CONTROL & GOVERNANCE
Give teams access.Keep admins in control.
Decide who can do what, which AI models each agent may use, and how much each person can send. Start simple, then switch on enterprise controls as you grow.
Everything a growing team needs to adopt AI safely.
Approved models per agent
Restrict which LLMs each agent can use, so teams only reach the models you trust.
Owner & member permissions
Turn features on, off, or restrict them to named people, from creating agents to connecting tools.
Security events log
Review blocked messages, sensitive-data detections, and trigger-word hits in one owner-visible log.
Per-user rate limits
Cap how many requests each person can send per minute, configured for your account.
GitHub repository allowlists
Limit agents to the repositories you approve, and nothing else in your organization.
- VISIBILITY
- PERMISSIONS
- SECURITY
- COST CONTROL
TRUST
Built for teams that takesecurity seriously.
No badges for the sake of badges. Here's what protects your data today.
- Encrypted in transit and at restTLS on every connection, with database, storage, and credential encryption at rest.
- Envelope-encrypted credentialsIntegration secrets are sealed with AES-256-GCM and rotated nightly.
- Tenant isolationRow Level Security keeps each account's data separate at the database.
- Owner-visible security logEvery blocked message and trigger-word hit is recorded for account owners.
- Role-based accessOwner, member, and enterprise standard-user roles with granular permissions.
- Established infrastructureCohrt runs on industry-standard cloud providers, including Supabase and Vercel.
Security questions, answered
READY TO GET STARTED?
Give your team AI.Keep your data protected.
Start free, switch on the protections you need, and add enterprise controls as you grow.