Trust & safety

Everything we build starts with security.

Illana is a memory layer between your connected business systems and the AI tools your team already uses. Your organization keeps ownership of synced data, and Illana never trains models on your content.

How Illana protects your data.

The controls behind every answer — from isolation and encryption to deletion you control.

Per-account isolation

Each account is isolated in the vault. No cross-customer access in the application.

Encrypted at rest

AES-256-GCM for sensitive content and integration credentials in your vault.

Encrypted in transit

TLS for API, assistant, and web traffic across the production service.

Audit logging

Usage and access logging that never records full message bodies in routine logs.

Delete anytime

Source-level purge and full account deletion, controlled entirely by you.

No vendor lock-in

You choose the AI model and access path. Illana is never a single-vendor trap.

Questions your reviewers will ask.

Is my data encrypted?

Yes. Illana protects your information in transit and at rest using industry-standard controls appropriate for business and regulated environments.

In transit, all access to the Illana service — including the web application, API, and assistant connections — uses encrypted HTTPS (TLS).

At rest, sensitive content such as message bodies, document text, and integration credentials is encrypted using AES-256-GCM under keys controlled as part of your deployment. Storage-level encryption on the underlying database also depends on how and where you host Illana.

Metadata required for search and retrieval may be stored in your vault without the same field-level encryption. The white paper describes this split in more detail.

Does Illana train on my data?

No. Illana does not use your connected data — email, calendar, documents, transactions, or other synced content — to train foundation models.

Illana stores and retrieves your information. When you ask a question, relevant excerpts may be sent to the AI assistant you choose (for example Claude, ChatGPT, or your own application via the API). That provider's terms govern how they handle those requests. Illana does not add your vault to a shared training corpus and does not sell or license your content to third parties.

Can our data stay inside our infrastructure?

Yes. Illana is designed so your memory vault can run in infrastructure your organization controls — your cloud account, private network, or on-premises environment.

In a self-hosted or private deployment, synced data remains in your database. Illana does not operate a shared pool of customer memory for enterprise deployments. Access to the vault is limited to Illana application services on your network; the database should not be exposed directly to the public internet.

If you use Illana as a hosted service, data is processed in Illana's production environment but remains isolated per account and is not commingled for model training. Organizations with strict residency or boundary requirements should contact us to discuss deployment options.

How are credentials stored?

Credentials and secrets are never stored in plain text in the application.

  • Account passwords are stored as one-way cryptographic hashes.
  • API keys are stored as hashes only. The full key is shown once at creation and cannot be recovered later.
  • Integration tokens (email, calendar, banking, Slack, Teams, and similar connectors) are encrypted in your vault and used only by background sync services — not by the public web tier.

Encryption keys for the vault are configured as deployment secrets and are not checked into source control.

Can we delete everything?

Yes. You control retention and erasure.

  • Per source: disconnecting an integration with purge removes the data Illana ingested from that source.
  • Full account: account deletion disconnects integrations and removes your memory items, related records, and stored credentials from the vault.
  • Access: API keys and assistant connections can be revoked at any time from your account settings.

Deletion applies to data held in Illana. Copies in upstream systems (for example your email provider or document store) are not affected.

For enterprise evaluation

A path from first look to production.

Product reviewSecurity reviewPilotProduction

Start with the questions above and the white paper, then email us for a completed security questionnaire or an architecture walkthrough.