---
title: "Most AI proposals never get past IT. This one is built for that conversation."
url: "https://referent.app/security"
description: "Single-tenant isolation, zero-retention model providers, permissions mirrored from your own systems and no duplication of your data. How Referent is built to clear a security review."
---

Security

# Most AI proposals never get past IT. This one is built for that conversation.

Tools that train on company data, store it, or ignore access permissions do not clear a security review. Referent is designed around the opposite defaults: your data stays in its system of record, the model providers retain nothing, and every answer respects the permissions you already enforce.

[Book a demo](/demo)[Talk to us](mailto:hello@referent.app)

Architecture

## Four properties that decide the review.

These are structural, not policy promises layered on afterwards.

01

### Single-tenant isolation

Your deployment runs in its own environment with its own storage and its own credentials. There is no shared index and no shared vector store. Another customer's workload cannot reach yours because it does not run in the same place.

02

### Zero-retention model providers

Referent runs against providers under zero-retention agreements. Prompts, responses and metadata are not stored after the request completes and are never used to train a model. A question serves the moment it was asked and then it is gone.

03

### Your permissions, mirrored

Access is inherited from the systems themselves rather than reimplemented in a second place. If someone could not open a record yesterday, they cannot get an answer built from it today. Nothing widens as a side effect of the deployment.

04

### No data duplication

Answers are fetched from the live system at the moment the question is asked. Referent does not build a parallel copy of your database, so there is no second store to secure, to keep in sync, or to delete later.

Governance

## Controls that map to how your team already works.

*   ### Scoped by system
    
    You decide which systems Referent can reach and what it may do in each one. Read-only is a valid configuration and a common starting point.
    
*   ### Auditable by default
    
    Queries and actions are logged, so the question of what was asked and what was retrieved has a factual answer rather than an estimate.
    
*   ### Citations on every answer
    
    Each answer points back to the record it came from. Verification does not depend on trusting the assistant.
    
*   ### GDPR
    
    European data protection requirements are part of the deployment design, including data residency discussions before anything is connected.
    
*   ### Deployment location
    
    Where the deployment runs is a decision made with you, not a default you inherit.
    
*   ### Nothing to unwind
    
    Because there is no migration and no duplicated store, removing Referent does not leave a copy of your data behind.
    

On certifications

We publish the properties we can substantiate. If your review needs specific certification evidence, ask us directly and we will tell you exactly where we stand rather than putting a badge on a page.

## Bring your security team to the first call.

[Book a demo](/demo)[Sign in](https://dash.referent.app/onboarding)

## Be the first to hear about Referent news.