Trust & security — Living Maps

How this instance handles your data. Every statement below is enforced by the software, not policy alone.

Data at rest
The entire database — uploaded files, synced rows, source credentials, geocode cache — is encrypted with ChaCha20 under a key held only by this instance. Production refuses to start without it.
Data in transit
All traffic is served over TLS. Source fetches prefer HTTPS and are blocked from reaching internal or private network addresses.
Tenancy
This is a single-tenant instance: its own containers, its own database, its own encryption key. No other customer's data shares this deployment.
Who can view a map
Map links are unguessable 192-bit tokens, private by default. Maps can additionally require a viewer password, and embeds can be limited to approved domains.
Who can change a map
Authoring requires the admin password. Every publish, restyle, re-upload, and delete is written to an append-only audit log.
AI processing
Enabled, served by broker. The assistant is READ-ONLY: it can propose view changes (filters, colors, basemap) and read aggregate answers, but every response is validated against a strict schema and clamped to this map's real layers and values before anything is applied. It cannot write to your data, and it never changes saved map configuration.
AI audit trail
Every AI call is logged with its purpose, provider, and validated result. Admins can review and export the log.
Model training
Your data is never used to train models. When served by a self-hosted model, data never leaves this server at all.
Data lifecycle
Uploads that are never published are purged after 24 hours. Deleting a map deletes its layers, rows, and cached geometry.
Failure honesty
Rows that cannot be placed are counted and shown, never silently dropped. A failed refresh keeps the last good data and says so, rather than serving stale data as current.

Questions a review needs answered that aren't here? Ask the instance owner — this page is generated from the running configuration.