Verify the boundary before production.
Identity, data flow, retention, and evidence.

Spotonix is the AI analyst that interprets before it queries. This is the page you send to your security team. It names the decisions that must be explicit for a production deployment: where components run, which credentials they use, what data crosses each boundary, which artifacts persist, and which system enforces access.

Spotonix does not use website shorthand as a substitute for a security review. Deployment claims carry an engagement status until the actual topology and evidence are confirmed.

The review model

Three boundaries to document.

Most review errors come from collapsing three different questions into one: where application artifacts live, which model endpoint receives context, and which warehouse credential executes SQL. Record each answer for the deployment under review.

01 · Hosting & retention

Where each artifact lives

Document the application runtime, Context Graph, prompts, logs, caches, query results, backups, and deletion path. Hosting and retention are deployment decisions, not universal claims inferred from the product category.

02 · Model

Which endpoint receives what

Spotonix supports configurable Anthropic and OpenAI backends. Confirm provider, model, endpoint, key owner, region, data-usage terms, retention settings, and the context included in each request.

03 · Warehouse identity

Which credential executes SQL

The current implementation uses a configured database connection. Confirm whether the selected deployment uses a service identity, delegated user identity, or another credential mode, then test table, row, and column restrictions with representative users.

The request path to review

1

User submits a business question

2

Configured model backend helps interpret it

3

Analysis plan becomes visible

4

SQL is generated and its bindings checked

5

Configured database connection executes the query

For each step, record the component, operator, region, credential, input, output, log, retention policy, and deletion path. See Intent Algebra for the product behavior and Architecture for the component path.

Evidence to collect

Turn each security claim into a test.

A security claim is useful only when the evaluator can identify the enforcement point and the evidence. The current site deliberately does not mark an identity or residency control live without deployment-specific proof.

Which tables a user can query

Credential mode plus denied/allowed query tests

Data-platform and security teams

Row- and column-level restrictions

Representative row/column policy test results

Warehouse owner

Who a person is

Authentication flow, session policy, provisioning, and off-boarding test

Identity and security teams

What a shared Answer reveals

Stored-result policy and a cross-user access test

Application and data owners

The output of this review should be an approved data-flow diagram and control matrix for the deployment—not a screenshot of a marketing promise.

Where the boundary is

Claims that remain conditional.

These may be valid for a particular topology, but they are not published as universal live controls until supporting evidence is available.

  • "No data egress." Requires a complete data-flow inventory covering model requests, query results, telemetry, logs, caches, support access, and backups.
  • "Your model, your contract." Requires the selected endpoint, credential owner, commercial relationship, and data-usage terms to be documented.
  • "Runs as the user." Requires delegated warehouse identity and access-policy tests. A configured service credential is a different model and must be described as such.
  • "No training on your data." Requires provider terms and deployment settings; it cannot be inferred solely from the Spotonix application design.
  • "No query on a guess." In Copilot mode the plan gate can pause generation, but some assumptions are allowed by design. Test the ambiguity classes that matter to your use case.

Controls & assurance

What your security team gets to hold.

Each item below is stated at the status it has actually reached. Where something is not yet generally available it is labeled as such — Spotonix does not describe roadmap as if it shipped.

Identity & SSO

Engagement

Confirm the authentication method, identity source, role mapping, provisioning, deprovisioning, session controls, and administrative access for the deployment.

Warehouse permission model

Engagement

Confirm the configured database identity and verify warehouse grants, row policies, and column policies with representative permitted and denied requests.

Data residency

Engagement

Confirm regions and storage locations for compute, graph artifacts, logs, results, caches, backups, observability, and support workflows.

Interpretation and query trace

Engagement

The plan is visible in the analysis workflow. Confirm retained plan identity, query linkage, timestamps, actors, export, tamper controls, and log-retention requirements.

Model governance

Live

Anthropic and OpenAI model backends are configurable. Provider choice, key ownership, endpoint, region, retention, and model-change policy are engagement decisions.

Context Graph portability

Live

The Context Graph is your asset. Open export of the graph in a standard, non-proprietary format — so your definitions leave with you — is in development. We will confirm the format and scope with design partners rather than overstate it here.

Third-party attestations (SOC 2 and similar)

Roadmap

A SOC 2 attestation is not currently held. Spotonix does not claim certifications it has not earned, and this page will not imply one. When an attestation is finished we will publish the report and its scope; until then, ask us directly and we will share exactly where the process stands.

Deployment topology, network boundaries, and control specifics are confirmed per engagement. We work these through with your security team against your real environment, not a reference diagram — and we would rather answer a hard question in a review than pre-answer it loosely here.