Designed by veterans of regulated industries who have lived through complex security and compliance requirements.



| Sub-processors | AWS / GCP (storage & orchestration); OpenAI / Anthropic / Google Vertex AI Full list in our Trust Center → |
| DPA & Security Questionnaire | |
| Trust Center | trust.slateo.ai |
Queries run directly in your warehouse, with traffic routed over private links or VPC wherever possible. Raw data is never ingested into a central store.
Components that touch data sit behind their own boundary, away from UI/API. Humans fetch results via presigned, time-bound URLs; agents and services use short-lived federated identities instead of static credentials.
Your identity provider or warehouse remains the single source of truth. Policies like row-level security apply at the source, with least-privilege access enforced throughout.
Choose deployment style, bring your own keys, configure retention settings. Full visibility into how your data is processed and stored.
Three-tier isolation model ensuring your data never leaves your control
Your browser, identity provider, and data warehouse remain under your complete control. All authentication and authorization policies are enforced at the source.
Multi-tenant API server handles workflow orchestration and metadata management. Never touches raw data - only coordinates secure operations.
Isolated workers with encrypted DB credentials execute queries in your warehouse. AI agents process results in ephemeral, secure containers.
Workers run queries via your service or user identity. Warehouse policies (e.g. row-level security) are enforced at source.
Results and metadata (output schema, row count, timestamps) are stored in org-scoped storage and encrypted at rest.
Browser downloads results via presigned, time-bound links over TLS. The API never proxies raw result rows.
Temporary artifacts are cleared; caches can be invalidated or purged; retention defaults are provided with admin control.