Records are encrypted on your device.
Source records are encrypted client side before they are written to your vault, rather than sitting there as readable documents.
ManyKind Findings / vault / models / permissions / deletion
Security is not a badge. It is a set of explicit decisions about what is stored, who holds the key, what reaches inference, what a model may claim in a Finding, and how access ends.
The actual boundary
These statements are deliberately specific. Private should describe an inspectable system, not an atmosphere.
This preview and the sample workspace are operated by ManyKind, based in the EU. Where a dedicated deployment runs, and who operates it, is agreed per engagement. Deployments your organisation controls is what the system is designed for, not a per-deployment claim about how any given customer has configured it.
Source records are encrypted client side before they are written to your vault, rather than sitting there as readable documents.
A new device needs both an emailed sign-in code and the recovery key you saved.
Access to the email account alone does not open the vault.
On a query, your question and the source text authorised for that matter go to a dedicated inference endpoint.
So we do not claim that document content never crosses that boundary. It does.
Calculations run on inspectable derivation logic where it is supported, and written summaries stay constrained by exact source quotations.
The challenge step confirms that a displayed quotation exists in the source it cites.
It does not validate a legal conclusion. That judgment stays with the lawyer and the reviewer.
If the authorised record cannot support a conclusion, you get an insufficient-evidence Finding instead of an invented bridge across the gap.
User controls
Permissions and removal belong in the product, not in a buried policy page.
See which files and connected records a matter can use.
VisibleAuthorise sources per matter, not one undifferentiated account.
ControlledDisconnect a source or revoke access for a matter when its job is done.
ReversibleRemove a workspace and its working record from the product controls.
User initiatedRestore access on a new device with your recovery key.
Recovery keyManyKind Findings / security as a product boundary
See how these boundaries connect to the derivation and review record behind every Finding, or bring one real matter to a working session.