Everything the agent does is on the record
A complete trail, per run
Every agent run is written to an append-only log scoped to your workspace: what was asked, which tools were called, what those tools returned, which model produced the answer, and what it cost. There is no path through the product that skips it — a scheduled run leaves the same trail as someone typing in Slack.
Yours to export
Admins can export the log whenever they want, filtered by member, date range or tool. It is a record you keep, not a dashboard we rent you. If you leave, you take it with you.
Secrets stripped before anything is stored
Credentials, keys and tokens are detected and removed before a line is written, so material that passes through an agent doesn't come to rest in the log. Treat the output as safer than raw rather than guaranteed free of personal data — broader detection is coming, and we would rather you knew the difference.
How we handle your credentials
Encrypted under keys scoped to your workspace
Every credential you connect — Slack tokens, OAuth grants, the API keys behind the tools you attach — is encrypted at rest under keys that belong to your workspace alone. All traffic is encrypted in transit.
Customer-managed encryption keys
Supplying your own encryption key — so that we cannot decrypt your data without your cooperation, and revoking it renders the data inert including to us — is coming rather than shipped. If it is a hard requirement rather than a preference, talk to us before you buy.
Least privilege, by default
Gauss asks for the narrowest set of permissions that let it do the job — read the messages that mention it, reply to them, and reach the tools you have explicitly connected. It cannot post into channels you haven't invited it to. Secrets never appear in our source, our build output or our logs.
Where your data lives
Workspaces are isolated from each other
Each workspace can only ever reach its own data, and that boundary is enforced at every layer rather than trusted to application code. Within a workspace, each member only sees what their role permits.
Residency
Customer data is held in the United Kingdom by default. Dedicated deployments run wherever you need them to.
Dedicated deployment
Enterprise customers with the strictest sovereignty requirements can run Gauss as a dedicated single-workspace instance inside their own cloud account, with their own model keys, so no customer data leaves their environment. We deploy and operate it; you keep root access to the account. Gauss is commercial software — a dedicated deployment means your own isolated instance, not a copy of the source.
How your data reaches a model
Managed
On the standard tiers we hold the upstream model keys, and what you send to Gauss is passed to the provider you have selected under our account. Provider terms forbid training on that traffic, and we authorise no other use of it.
Bring your own key
Higher tiers can supply their own model-provider key. Traffic then runs under your account and the provider bills you directly; we charge only for the platform that carries it. In this mode there is no relationship between us and the model provider for your data.
Bring your own model
Point Gauss at a model you host yourself and your prompts never reach a third-party provider at all.
Access controls
Sign-in
Dashboard access is through your existing Slack or Google identity. We never store passwords, and sessions are short-lived. SAML and SCIM are coming for enterprise.
Roles
Three roles — owner, admin and viewer. Owners and admins manage integrations, models, members and workspace instructions; owners alone can rename the workspace, grant ownership or remove another owner or admin. Viewers can read their own runs and change nothing.
Certifications and audits
- SOC 2 Type II — engagement in progress with a Big Four auditor. Report available on request under NDA once the observation window closes.
- GDPR / UK GDPR — data processing agreement available for enterprise customers.
- HIPAA — available on the Enterprise Dedicated tier with a signed BAA.
Security reviewers who need more depth than this page carries should email security@gaussintelligence.io — we answer architecture questionnaires and share detail under NDA.
Reporting security issues
If you discover a security vulnerability, please email security@gaussintelligence.io with details. We aim to respond within one business day.
Please do not publicly disclose issues before we've had a reasonable window to remediate. We're happy to coordinate on disclosure timing and credit researchers who report responsibly.
Coming soon
- Broader detection of personal data in the audit trail, beyond credentials.
- SAML and SCIM for enterprise customers.
- Customer-managed encryption keys on Enterprise Dedicated and above.
- Additional regions for latency-sensitive customers.
- FedRAMP and HITRUST for Custom-tier engagements as demand justifies.