Security

How PG Docs AI protects your documents — architecture first, promises second.

Tenant isolation by construction
  • Every workspace-owned table carries an indexed tenant_id, and all data access flows through a tenant-scoped repository that injects the workspace filter at query construction — domain code cannot forget a WHERE clause because it never writes one.
  • Object storage paths are workspace-prefixed; the API resolves the active workspace from a verified membership on every request.
  • Cross-tenant access attempts return 404, not 403 — the existence of another workspace is never confirmed. Isolation is enforced by a dedicated test suite that tries to read another tenant's documents, insights and reports.
API keys and credentials
  • Workspace AI-provider keys are encrypted at rest with Fernet (AES) and are write-only: the API only ever returns whether one is set and its last four characters.
  • Workspace API access keys (pgda_…) exist only as SHA-256 hashes; the full key is shown once at creation. Revocation is immediate.
  • API keys are bound to their workspace at issue: a leaked key cannot be pointed at another workspace via a header.
  • Application secrets live in environment variables or a managed secret store — never in code or logs.
Transport and data
  • TLS in transit everywhere; documents and derived data encrypted at rest at the storage layer.
  • Passwords are hashed by the identity provider (Better Auth); the API never handles credentials — it validates short-lived signed JWTs.
  • Structured logs carry request and workspace identifiers, never document contents.
Citation integrity
  • Generated artifacts cite a numbered source list built from the workspace's own indexed chunks. Markers that do not exist in the list are stripped before the response reaches you.
  • The system prompt forbids filling gaps with outside knowledge and instructs the model to say when the documents do not contain the answer.
Operations
  • Per-workspace rate limiting (requests per minute and tokens per day) with plan-aware ceilings, enforced before any model call.
  • Every LLM call is metered: tokens, cost, latency and status — including failed and interrupted calls.
  • Background processing is idempotent and retried with backoff; a failed ingestion marks the document as failed with the reason.
Self-hosting
  • The full stack (web, API, worker, PostgreSQL with pgvector, Redis) is open source and deployable in your own cloud via the included Terraform — your data never leaves your boundary.

Reporting a vulnerability

We treat security reports with priority. Email security@pgsofts.org with details and a reproduction if possible; we will acknowledge within 2 business days. We do not pursue good-faith research that respects privacy and avoids service degradation. See the privacy policy for data handling details.