NewSnippets: tell the AI about you and your company once.See how New modelClaude Sonnet 5.5 is now available.Read more
TRUST & SECURITY

Powerful AI, under your control.

Chat, agents, workflows and every connected system run in one workspace, under one set of controls and one privacy log. Here is exactly what that means for your data, and what you can check for yourself in the product.

Guardrail policies
EU data residency
Workspace data is stored in the EU by default. Models that cannot meet your residency settings are greyed out.
Zero retention, as a switch
Turn it on and only providers that contractually keep none of your data may run your prompts.
Redaction before the model
Card numbers, credentials, IDs and your own patterns are warned about, redacted or blocked before a prompt leaves.
A record you can export
Every guardrail trigger and policy change lands in the privacy log, filterable and exportable.
Your data

Where it lives, where it goes, and who can reach it.

No surprises buried in a sub-processor list. These are the defaults, and most of them are yours to change.

Encrypted in transit
Every connection to the app, the REST API and the MCP server runs over HTTPS. At-rest details are in the documentation pack.
Workspace and personal, kept apart
Workspace connections are shared with everyone in the workspace; personal connections, like your own Google Drive, stay yours. Knowledge bases have their own member lists.
Read-only by default
Database connections can be read only (SELECT and nothing else), read & write, or full access. CRM connections stay read-only until you allow writes.
Zero data retention, enforced
Switch on zero data retention and only providers that contractually do not retain your data may be used. The rest drop out of the model picker.
You choose the region
Storage in the EU by default, US hosting on request for Enterprise. Require EU-served inference, and models that can only serve elsewhere are blocked rather than quietly used.
Your keys, optionally
Bring your own provider keys from Business up, or, on Enterprise, run open-weight models on infrastructure dedicated to you so prompts never reach a third-party AI service.
IN THE PRODUCT

The region is a setting, not a promise.

Workspace settings, Data Residency. Storage sits in the EU unless you ask otherwise, and two switches narrow inference further: EU-served endpoints only, and zero data retention only. The page shows how many models remain usable as you flip them.

Data residency: EU storage by default, EU-served inference and zero-retention constraints 1 EU storage by default 2 Inference narrowed further
Identity & access

Who gets in, and what they can reach.

Sign-in, roles and teams are managed in the workspace. Every integration is scoped to the workspace or to one person.

Sign-in
Google sign-in, or email and password with email verification for every new account.
Domain-based joining
People with your company email domain can join the workspace without an invite. Everyone else is invited, and pending invites are listed.
Roles and teams
Owner and Admin roles for the workspace. Teams with owners who approve shared prompts and manage the team's budget.
Provider access per team
Admins allow a provider for everyone, block it, or open it to named teams only. Admins can always use every model.
IN THE PRODUCT

API keys carry permissions, not a master pass.

One key works for the REST API and the MCP server, and each key holds only the permissions ticked for it - read, manage and delete are separate. A key never gets more than its owner has, and model access, residency and guardrails still apply to every call.

API keys: one key works for the REST API and the MCP server 1 One key, REST and MCP
Private network access

Reach systems that never touch the public internet.

Plenty of the data worth asking about lives in a database with no public endpoint - the reporting replica, the order database behind a VPN. StickyPrompts reaches it through a jump host you control, so the database itself is never exposed to the internet.

How the connection works
StickyPrompts
Connects from one fixed IP address, with a key it shows you.
Your jump host
An SSH host you run. You allow the IP and authorise the key.
Your database
PostgreSQL, MySQL, MariaDB or SQL Server, still private.
✓ One IP to allow, one key to authorise, and removing the key cuts access. Read only unless you choose otherwise.
  • Reach a private database through your own jump host
  • StickyPrompts connects over SSH to a jump host you control, from one fixed IP address you allow-list.
  • Key-based: add the public key StickyPrompts shows you to the SSH user's authorized_keys, and remove it to revoke access.
  • Works with PostgreSQL, MySQL, MariaDB and SQL Server databases that have no public endpoint.
  • Choose the permission level per connection - read only (SELECT), read & write, or full access - and the SSL mode.
  • Guardrails can scan the data that comes back, and every trigger lands in the privacy log.
The model boundary

Nothing leaves the workspace unexamined.

Chat messages, agent steps and scheduled workflows run under the same workspace rules, and the guardrails scan what goes in, what tools return and what comes back.

  • Provider access rules: allow, block or limit each provider to named teams
  • Zero-data-retention providers only, as one switch
  • Sensitive info and secrets redacted before a prompt leaves the workspace
  • EU-served inference endpoints only, as one switch
  • Open-weight models on infrastructure dedicated to you, on Enterprise
  • Provider keys you own, from Business up
Guardrails & residency 4 active
Privacy log
REDACTED4111 1111 1111 1111 → [payment_data]
REDACTEDHU42 1177 3016… → [payment_data]
REDACTED+36 30 555 0142 → [phone]
BLOCKEDmessage contained an API key
POLICYmodels limited to EU-served endpoints
Every trigger is recorded. Filter it, export it.
THE SAME CONTROLS, IN THE PRODUCT

The demo above is illustrative. These are the real screens, from a demo workspace.

01 · Model allow-lists
Model & provider access: allow, block or limit providers to specific teams 1 Allow, block or limit

Allow, block or restrict each provider, category and model - per team if needed. Models your residency policy rules out are greyed out for everyone.

02 · Redaction rules
Sensitive info detection: choose surfaces and warn, redact or block per detector 1 Card numbers: redact 2 Credentials: block

Choose the surfaces to scan - user input, tool data, model output - and warn, redact or block per detector.

03 · What the model receives
A chat where card numbers and a phone number were redacted before the model saw them 1 Masked before the model

The card number, IBAN and phone number were replaced before the prompt left the workspace, so the draft works around placeholders.

04 · The record of it
The privacy log (AI Act): every redaction and policy change, exportable 1 Exportable

Every redaction and every policy change lands in the privacy log, filterable by area and action, and exportable for a review.

For your security review

Send us your questionnaire - we'll do the work.

Evaluation shouldn't stall because a vendor takes six weeks to answer a spreadsheet.

Documentation pack
Architecture and data-flow diagrams, the sub-processor list, retention defaults and our DPA.
Security questionnaire
Send yours - VSA, CAIQ or your own spreadsheet. We complete it as part of evaluation, not after signature.
Testing evidence
Ask for our testing evidence and how we handle vulnerabilities. We share what exists and say plainly what does not.
Frameworks & attestations
LogiNet is certified to ISO 9001; ISO 27001 and SOC 2 are underway. Tell us which frameworks your review needs and we'll share exactly what we hold today.
CERTIFICATION STATUS

LogiNet, the company behind StickyPrompts, is certified to ISO 9001. ISO 27001 and SOC 2 are underway and not issued yet, so neither gets a certified badge here. This is where each one actually stands, and each certificate goes up the day it exists.

  • ISO 9001

    Quality management. How LogiNet runs delivery, reviews work and handles what goes wrong, written down and audited by a third party.

  • ISO 27001

    Information security management. Controls, risk treatment and evidence across the platform and the company around it.

  • SOC 2

    Type II readiness for customers whose review process asks for it rather than for an ISO certificate.

FOUND SOMETHING?
Report it to security@stickyprompts.com. A person reads every report and replies to the reporter.
Contact security
Trial
A $5 balance to start. No card needed.
Bring it to your security team

Roll out AI your CISO can sign off on, with the evidence.

Start free, set the guardrails, connect one system, and hand the privacy log to whoever needs to see it.