Current and planned providers
Provider controls
Provider access must be limited to what is necessary. Secrets must remain outside Git. Contracts, data-processing terms, regions, retention, breach notification and deletion capabilities should be reviewed before unrestricted commercial launch.
AI providers
Kimi or another external AI provider is not enabled for customer operational data by default. Documentation-only assistance may be activated separately. Client file content, metadata or operational context must not be sent to an AI provider without an approved purpose, tenant setting and documented data treatment.
Changes
Material provider changes should be published on this page before or promptly after activation, subject to emergency security requirements. Clients requiring advance notice should use a written enterprise agreement.