Back to Home
    Trust and Security

    Security your IT team can sign off on.

    OwnerLM runs on tenant-isolated, audited infrastructure. Your portfolio data stays yours. It is never sold, never shared across customers, and never used to train foundation models.

    OwnerLM is operated by AI Everywhere Corporation.

    Encryption
    TLS 1.2+ in transit, AES-256 at rest
    Isolation
    Row-level security on every tenant table
    AI training
    Your content is never used to train models
    Bank credentials
    Tokenized by our PCI-compliant aggregator

    Your data stays yours

    • We do not sell, rent, or trade your data. Period.
    • Your documents, emails, transactions, and chat history are visible only to your workspace.
    • We never use your raw content to train foundation models. Product improvements come from anonymized, aggregated telemetry only.
    • You can export anytime through the app and delete any document, conversation, or your whole account.

    How isolation works

    Every customer gets a fully isolated tenant. Documents, embeddings, financials, and chat history are scoped at the database row and the storage bucket. There is no shared pool, and there is no admin view that spans customers.

    • Row-level security on every table. Database policies scope every read and write to your workspace. There is no shared "all customers" view, even for our own staff queries.
    • Per-tenant storage. Uploaded documents live in tenant-isolated buckets so a misconfigured share link cannot leak across customers.
    • Role-based access. Team members get Owner, Manager, Editor, or Viewer roles, and access can be scoped to specific portfolios or properties.
    • Guest portals. When you share a deal with a lender or broker, you choose exactly what they see. Raw financials can be hidden while leaving the risk dashboard visible. Every guest action is logged.
    • Magic links. Public shares use signed, expiring URLs. You can revoke access at any time.

    Encryption and infrastructure

    • All traffic is encrypted with TLS 1.2 or higher.
    • All data at rest is encrypted with AES-256.
    • Production runs on managed Postgres with point-in-time recovery and automated backups.
    • Development, staging, and production are fully separated. Production credentials are not reused.
    • Service accounts run with least privilege. No shared admin passwords.

    Identity and sign-in

    • Your brand on connected accounts. When your team connects a productivity account, the consent screen uses your own client ID. Your brand, not ours.
    • Breach-checked passwords. Every new or changed password is checked against a known-breached-password database and rejected if compromised.
    • Session controls. Sessions expire and can be revoked. Team owners can remove a member's access in one click.
    • Workspace ownership. The primary workspace creator is the only one who can demote other owners. Privilege escalation is blocked at the database level.

    AI boundaries

    • We use frontier large language models to read your documents and answer questions. Those providers process content under enterprise terms and do not retain it for training.
    • Every AI answer includes citations that link back to the exact source document and page so your team can verify the model rather than trust it blindly.
    • Extraction goes through a compare-and-confirm review step before high-stakes data lands in your audits and dashboards.
    • Background skills only see data inside your workspace and the public web sources you point them at.

    Why the AI answers you can trust

    Large language models are probabilistic. Our job is to make sure the answer that reaches your team is not. Three layers sit between raw model output and anything that touches your scorecards, audits, or reports.

    • Guardrails on every extraction. Every number pulled from a PDF or spreadsheet is validated against expected ranges, format rules, and canonical GL codes before it lands. Out-of-range values are flagged, not silently written.
    • Compare and confirm. High-stakes extractions like rent rolls, financials, and audit line items go through a review queue where the AI proposal sits next to the source cell or line. Nothing enters your audit record without a human confirm or a saved trust policy.
    • Cross-source reconciliation. When the same KPI shows up in two places, weekly report versus rent roll versus PMS sync, we reconcile them and flag the discrepancy on the property scorecard instead of picking one silently.

    Subprocessors

    We rely on a small set of vetted infrastructure and service providers, all under data-processing agreements that prohibit using your content to train AI models or for any purpose outside operating the service for you.

    CategoryWhat it does
    Cloud infrastructureManaged Postgres database, object storage, serverless compute, and hosting
    AI processingLarge language model inference under enterprise no-training terms
    Document parsingConversion of PDFs and spreadsheets into structured text
    Transactional email, SMS, and voiceDelivery of notifications and channels you have opted in to
    PaymentsPCI-compliant subscription billing. We do not store card numbers.
    Optional user-connected integrationsProductivity, file storage, banking, calendar, and property management systems you authorize, plus public web and licensed market data sources
    Named validators
    • Stripe handles billing under PCI DSS. We never see or store card numbers.
    • Plaid tokenizes bank credentials. Read-only scopes, revocable in one click.
    • Google and Microsoft handle SSO. Consent screens use your own tenant's client ID, never ours.
    • Compliance program managed under a documented control set. Third-party attestation is in progress. Current control mapping is available on request.

    Enterprise customers can request a detailed, current vendor list under NDA at security@ownerlm.com.

    Operational rigor

    • Centralized logging across the app, edge functions, and database.
    • Background dispatcher pattern with job locks so a stuck task cannot stack and overwhelm the system.
    • Anomaly alerts route to our on-call channel for fast triage.
    • Code review on every change, automated security scans on the public schema, and a weekly competitor and infrastructure review.

    Your controls

    • Export. Download your documents and AI outputs whenever you want.
    • Delete. Remove any document, conversation, or your entire account. Embeddings and extracted data are removed with the source.
    • Disconnect. Unlink any bank, Google, or PMS connection in one click. Sync stops immediately.
    • Retention. Active accounts keep data as long as you do. After account termination, all associated data is permanently deleted within 30 days.

    Compliance and disclosure

    • SOC 2 Type II: In progress. Happy to share our current control mapping and roadmap on request.
    • DPA: Available for enterprise customers. Email security@ownerlm.com.
    • Vulnerability disclosure: Found something? Email security@ownerlm.com. We respond within one business day.
    • Privacy: Read the full Privacy Policy for collection, retention, and subject-rights details.
    Questions from your IT or InfoSec team?
    AI Everywhere Corporation answers security reviews directly. No gatekeeping.
    security@ownerlm.com