Security you can only see in a diagram is a promise. Amzaa's isolation is enforced by the database itself, not by the interface. Here is how it works, and, because we are pre-launch, an honest account of what is in place and what is still ahead.
Row-level security is enforced by the database, so a query for one tenant physically cannot return another tenant's rows. It is not the application choosing to filter. It is the data layer refusing to hand them over.
Data is encrypted in transit over TLS and at rest, with secrets held outside the codebase. Sensitive values are encrypted at the field level where they warrant it.
Your data is yours. It is not used to train models, ours or anyone's. The AI rail proposes from your data in the moment; it does not absorb it.
Every write is hash-chained and sealed. Tamper with any row and verification fails from there onward. Publishing the root to you, held outside our database, is designed and scheduled rather than shipped. Isolation and evidence, not just access rules.
The AI never writes to your data. It proposes; a human approves; the engine writes. One switch stops every agent at once and fails closed. Every proposal and approval is sealed. The boundary is structural, not a rule an operator has to enforce by hand.
Security for AI is not a filter in front of a model. It is a rail the model runs on.
We are pre-launch, and we would rather you hear this from us. Formal certifications such as SOC 2 are not yet in place; they are on the roadmap, and we will show them when they are real, not before. Some of the strongest capabilities covered by our provisional patent applications, time-travel replay and legal hold among them, exist in the foundation and are being brought to the surface deliberately, schema first.
A vendor that hides its gaps is a vendor you will stop trusting the moment you find one. So there they are.
Most platforms answer this with a diagram and a hope. Amzaa is multitenant natively rather than as a layer bolted over a single-tenant product, which is what makes the shared model safe and the dedicated model possible without a different codebase.
Every tenant's rows carry their tenant, and the database refuses to return anything outside the caller's tenant. The rule lives in the database, so a forgotten filter in application code cannot leak data. It is not a query convention that everyone has to remember.
Some regulators, and some procurement teams, will not accept shared storage regardless of how the isolation is enforced. Because the platform is multitenant by design rather than by retrofit, running a tenant in its own database is a deployment decision, not a fork of the product. The same engine, the same configuration, the same sealed trail.
Isolation in the shared model is the part you can test rather than take on trust: it is enforced by the database, under a runtime role that has no way to step around it. We would rather you probed that than read a paragraph about it.
A small cohort of regulated banks, NBFCs and the firms that own them. Early access, real influence, pricing that holds.
We are pre-launch and we will not dress it up. There are no logos on this page because there are none to show. Come and try to break the chain.