ManyKind Findings / vault / models / permissions / deletion

The matter record needs clear boundaries.

Security is not a badge. It is a set of explicit decisions about what is stored, who holds the key, what reaches inference, what a model may claim in a Finding, and how access ends.

The actual boundary

What happens at each layer.

These statements are deliberately specific. Private should describe an inspectable system, not an atmosphere.

This preview and the sample workspace are operated by ManyKind, based in the EU. Where a dedicated deployment runs, and who operates it, is agreed per engagement. Deployments your organisation controls is what the system is designed for, not a per-deployment claim about how any given customer has configured it.

01 / Before storage

Records are encrypted on your device.

Source records are encrypted client side before they are written to your vault, rather than sitting there as readable documents.

02 / Key custody

Your device creates and holds the vault key.

A new device needs both an emailed sign-in code and the recovery key you saved.

Access to the email account alone does not open the vault.

03 / Query path

Inference receives your question and the authorised source text.

On a query, your question and the source text authorised for that matter go to a dedicated inference endpoint.

So we do not claim that document content never crosses that boundary. It does.

04 / Model boundary

The query path uses open-source models.

Calculations run on inspectable derivation logic where it is supported, and written summaries stay constrained by exact source quotations.

05 / Challenge

Cited quotations are checked against their sources.

The challenge step confirms that a displayed quotation exists in the source it cites.

It does not validate a legal conclusion. That judgment stays with the lawyer and the reviewer.

06 / Honest failure

Missing evidence stays missing.

If the authorised record cannot support a conclusion, you get an insufficient-evidence Finding instead of an invented bridge across the gap.

User controls

See the scope. Change the scope. End the scope.

Permissions and removal belong in the product, not in a buried policy page.

Source inventory

See which files and connected records a matter can use.

Visible
Scoped connectors

Authorise sources per matter, not one undifferentiated account.

Controlled
Revocation

Disconnect a source or revoke access for a matter when its job is done.

Reversible
Workspace removal

Remove a workspace and its working record from the product controls.

User initiated
Portable access

Restore access on a new device with your recovery key.

Recovery key

ManyKind Findings / security as a product boundary

Explicit enough to trust with a matter.

See how these boundaries connect to the derivation and review record behind every Finding, or bring one real matter to a working session.