Your workflow knowledge stays permissioned
RuleFoundry combines authenticated access, server-side authorization, private asset delivery, and scoped agent connections so real workflow knowledge is not treated like public prompt material.
Concrete controls, stated plainly
This is the current product posture—not a claim of certifications we do not list.
Server-checked access
Every customer-data read is checked against signed-in workspace, requester, interviewee, or invited-viewer access on the server.
Private provider credentials
AI and voice-provider keys stay on the server. They are not sent to the browser or a connected assistant.
Protected private assets
Private files are served through short-lived signed access after RuleFoundry confirms the requester is allowed to view them.
No training on customer data
RuleFoundry does not use customer workflow data to train models.
The browser, viewers, and plugins do not bypass the same rules
The RuleFoundry backend remains the authorization boundary across the product, including least-privilege marketplace connections.
Sign-in
Authenticated accounts and server-validated session tokens protect full customer content.
Workspaces
Personal and Team content is isolated by workspace membership and role-aware access checks.
Shared reviews
Completed Extractions can be shared with email-bound, read-only viewers without granting workspace rights.
Connected assistants
Cursor, Claude, ChatGPT, and GitHub Copilot connections use scoped, revocable OAuth authorization and the same backend permission rules as the web app.
Marketplace boundary
Marketplace connections can find permitted Extractions, read completed artifacts, and create an Extraction after the user confirms its topic, description, and participant. RuleFoundry automatically invites an external participant. The connection cannot begin, run, resume, complete, modify, resend, or delete an Extraction.
Operational logs
Application logging is designed to exclude transcripts, prompts, artifact bodies, credentials, and provider secrets.
Deletion
Deleting an Extraction removes its customer content and private files. Minimal billing and usage records may remain for accounting and abuse prevention.
When you ask a connected assistant to read permitted RuleFoundry content, the returned content is processed by that assistant provider under its terms, privacy policy, retention settings, and account controls. Disconnecting or revoking access stops future RuleFoundry reads but may not remove content already present in an assistant conversation.
TEAM AND ENTERPRISE
Start with Team. Add enterprise controls when rollout requires them.
Team provides a shared workspace, member roles, invitations, centralized billing, and workspace access control. Enterprise is the sales-assisted step for identity, governance, retention, procurement, and support needs.
Enterprise path
- SSO and SCIM provisioning
- Audit logs
- Custom retention requirements
- Security and procurement review
- Contracting and rollout support
Data handling questions
Use the privacy policy for the legal overview. Contact us before a pilot when you need an NDA, provider review, data-flow discussion, or a narrower test scope.
Review before relying on an output
RuleFoundry exposes the transcript, pseudo-logic, and open questions so people can review the result. It is a decision-support and documentation system, not an automatic sign-off authority.
Need a security or procurement review?
Tell us what your team needs to validate. We can scope the conversation before you put a sensitive workflow into the product.