Your AI should have boundaries. Your data should too.
An overview of practical controls Wiki applies to help protect customer knowledge and access.
Security approach
Wiki is designed to help customers govern knowledge, permissions, and proof behind AI answers. We apply reasonable safeguards intended to reduce risk, but no system is invulnerable.
Tenant isolation
Organization and workspace data is separated by tenant boundaries enforced in application logic and database access controls.
Identity and access
Production authentication uses industry-standard identity providers. Sessions are protected with secure cookie settings in production deployments.
Role-based permissions
Organization and workspace roles control who can view, edit, publish, configure policies, and manage billing.
AI policy controls
Customers configure AI applications, audiences, and access policies. Policy evaluation is applied before sources are used for answers.
Audit logging
Sensitive actions such as permission changes, publishing events, and governance updates are recorded in audit logs.
Encryption in transit
Traffic between clients and Wiki is encrypted using HTTPS (TLS).
Encryption at rest
Customer content stored in our database and object storage inherits encryption-at-rest capabilities provided by our hosting infrastructure. Confirm specific configurations with your deployment documentation.
Security headers
We deploy application security headers including Content-Security-Policy, HSTS in production, and frame protections.
File uploads
Uploads are validated for type and size. Dangerous file types are rejected.
Docs publishing
Public documentation visibility is controlled by customer-configured publishing rules. Customers should review content before publication.
Custom domains
Custom domains require verification before routing traffic to published docs.
Payments
Payment information is processed by Stripe. Wiki does not store raw card data.
Incident communication
Operational incidents affecting Wiki services are posted on our status page when applicable.
Responsible disclosure
Security researchers may report issues through our responsible disclosure process.
Your responsibilities
You remain responsible for content, permissions, publishing choices, and reviewing AI outputs before relying on them.
Security contact
Report vulnerabilities to security@wiki.co. General questions: hello@wiki.co.