Trust

Security at Capere AI

Capere is designed to keep each organization’s connected business data separated and to limit access to authorized users and services.

Data isolation

Application records are scoped by organization. Authentication and authorization checks are applied at service boundaries, and tenant context is carried through data access and AI workflows.

Credentials and transport

External-service credentials are encrypted at rest and are not exposed to browser clients. Data is transmitted over HTTPS, and production secrets are maintained outside the source code.

Controlled integrations

Connected firm systems and data providers use permission-based access. Capere requests only the access needed for enabled features, and availability may depend on permissions granted by an administrator.

AI safeguards

The public website assistant is separated from customer workspaces and cannot query tenant tools or private customer data. Product AI access is governed by the authenticated organization context and available source permissions.

Operational practices

We use request throttling, structured logging, monitored infrastructure, dependency review, backup and recovery controls, and production configuration checks. Security controls are reviewed as the platform evolves.

Responsible disclosure

If you believe you have found a security issue, email security@capereai.com with a clear description and steps to reproduce it. Do not access, alter, or retain data that is not yours.