Secure By Design

Your org's data stays in your org.

Conversations, knowledge, and datastore records are isolated per organization. Agents are permissioned, embeds are designed for secure website use, and visitors never get a free pass into another tenant's world.

How isolation works

Security is a product shape — not a checkbox afterthought

  1. 01

    Organization boundary

    Each organization gets its own data space for knowledge, conversations, and records.

  2. 02

    Permissioned agents

    Only the people and agents you allow can read or write inside that boundary.

  3. 03

    Scoped tools

    Subagents only get the knowledge, tables, and app connections you attach.

  4. 04

    Secure embeds

    Website widgets authenticate access so a pasted snippet cannot become a free-for-all API.

Capabilities

What “secure by design” means day to day

Practical boundaries buyers and IT teams actually ask about.

Per-organization isolation

Another customer's conversations and docs are not in your workspace — and yours are not in theirs.

Knowledge stays yours

Uploaded policies and product docs are searched inside your org boundary.

Datastore privacy

Leads, tickets, and feedback rows live with the organization that collected them.

Least-privilege helpers

A product-lookup helper does not need email send access — and should not get it.

Website embed safety

The public widget is built so visitors talk to your agent without exposing admin power.

Human access control

Team members see what their role allows — not every secret key and every table by default.

In practice

Questions security-minded buyers ask

Short answers without vendor jargon.

Is this shared multi-tenant soup?

Embage is built around organization isolation so your operational data is not casually mixed with other customers.

Can a visitor scrape our knowledge?

Visitors talk through the agent under the access rules you set — they do not get a raw dump of your entire library.

Who can change agents?

Builders and admins in your organization. The public embed cannot reconfigure your agent.

What about connected apps?

App connections are authorized per organization and attached only to the helpers you choose.

FAQ

Common questions

Do you store everything in one big shared database?

Embage is designed so each organization's conversations, knowledge, and datastore records stay isolated from other organizations.

Is the website embed a public open API?

No. The embed is meant for visitor conversations with your agent under controlled access — not unrestricted access to your admin data.

Can I limit what an agent can touch?

Yes. Knowledge sources, datastore tables, and connected apps are attached intentionally — especially via focused subagents.

Test Only

Your first friendly agent
is about 10 minutes away.

We’re in a public test — jump in, build a chatbot or voice agent, and forgive a few rough edges. Data may reset.

Test environment · No credit card required