Everything on this page is shipped, documented, and open source. Where a protection has limits, we state them — that’s what makes the rest believable.
Guardrails and single sign-on need the licensed Enterprise Edition. Everything else here — the audit trail, encryption at rest, end-to-end encryption, recovery and device revocation — runs on the free Community Edition too. See the comparison
A catalog of guard types, configured per group. Requests are classified on the way in; a risky one is rerouted to a protected model instead of being answered normally. Verdicts are cached so the check stays fast — and every decision lands in a log you can review.
Microsoft Entra ID single sign-on with a fully documented OAuth registration and login flow. SSO comes with the Enterprise Edition; the free Community Edition signs people in locally, with MFA and passkeys.
Structured events with filtering and retention — including login-anomaly detection that flags unusual sign-in patterns. Guardrail decisions sit alongside, so one place answers what happened and what the AI layer did about it.
A master key, an AES-GCM wire format, layered disk protection — and documentation that states the threat model, including what it does not protect against. We’d rather you know.
We select the providers behind Pia Cloud to be European companies processing in EU data centres, with a data-processing agreement in place for each. No US providers. That is our procurement policy for Pia Cloud — self-hosting or your own provider key keeps the question in your hands entirely.
With end-to-end encryption on, the admin console shows what exists — devices, item counts, sync state — while synced content stays unreadable, even to the operator. Prompts sent to a Pia Cloud model are processed on the server rather than stored, and with a self-hosted server or your own provider they do not reach ours at all. That separation is documented and demonstrable: exactly what a works council or data-protection officer asks for. Server-side data — managed personas, device and plugin metadata, trusted certificates — is generated on the server and therefore not end-to-end encrypted.
A recovery code lets encrypted data survive a lost or reset device. And the honest flip side: if the code is gone too, the data is unrecoverable — by design, because a backdoor for you would be a backdoor for everyone.
An enterprise policy file enforces defaults across managed installations — including how the assistant itself behaves — with rollout guidance for IT.
Every registered device is visible with its pairing status and sync cursors. A lost machine gets revoked — cut off from sync — without touching the account or the other devices. Delete it entirely when it’s truly gone.
Pods connect over a single inbound route with a narrow contract: what a pod can and cannot see is documented, and the operator plane is unreachable from chat.
Security questionnaires, DPO questions, threat-model deep dives — we answer them ourselves.