Isolated libraries
AvailableOne OpenAI vector store per organization, with the ID stored in a browser-denied Firestore location.
Security by design
Every protected request is checked against server-verified identity, organization membership, role, document ownership, and provider mappings before any company knowledge is searched.
One OpenAI vector store per organization, with the ID stored in a browser-denied Firestore location.
Firebase ID tokens are exchanged for secure HTTP-only session cookies and verified on protected routes.
Permissions are checked in the interface, APIs, Firestore rules, and Storage rules.
Employee questions enable only File Search. Unsupported requests are not guessed.
Provider file IDs must match search results, annotations, server mappings, document access, and organization ownership.
Questions, answers, citations, usage, feedback, and manager review status are retained in Firestore.
Firebase App Check is wired into the web client. Storage and Firestore enforcement is enabled by operators after monitoring valid production traffic.
Setup takes only a few minutes. No source is published without your team's approval.