Trust & security — Living Maps
How this instance handles your data. Every statement below is enforced by the software, not policy alone.
- Data at rest
- The entire database — uploaded files, synced rows, source credentials, geocode cache — is encrypted with ChaCha20 under a key held only by this instance. Production refuses to start without it.
- Data in transit
- All traffic is served over TLS. Source fetches prefer HTTPS and are blocked from reaching internal or private network addresses.
- Tenancy
- This is a single-tenant instance: its own containers, its own database, its own encryption key. No other customer's data shares this deployment.
- Who can view a map
- Map links are unguessable 192-bit tokens, private by default. Maps can additionally require a viewer password, and embeds can be limited to approved domains.
- Who can change a map
- Authoring requires the admin password. Every publish, restyle, re-upload, and delete is written to an append-only audit log.
- AI processing
- Enabled, served by broker. The assistant is READ-ONLY: it can propose view changes (filters, colors, basemap) and read aggregate answers, but every response is validated against a strict schema and clamped to this map's real layers and values before anything is applied. It cannot write to your data, and it never changes saved map configuration.
- AI audit trail
- Every AI call is logged with its purpose, provider, and validated result. Admins can review and export the log.
- Model training
- Your data is never used to train models. When served by a self-hosted model, data never leaves this server at all.
- Data lifecycle
- Uploads that are never published are purged after 24 hours. Deleting a map deletes its layers, rows, and cached geometry.
- Failure honesty
- Rows that cannot be placed are counted and shown, never silently dropped. A failed refresh keeps the last good data and says so, rather than serving stale data as current.
Questions a review needs answered that aren't here? Ask the instance owner — this page is generated from the running configuration.