| Security & Compliance |
| Zero Data Retention | Prompts and completions discarded after every response | Pro & above |
| Abuse Monitoring OFF | No human review, no prompt logging, no side-channel collection | Enterprise ZDR |
| End-to-End Encryption | Zero-knowledge chat — not even Blackbox can read your content | Enterprise |
| SOC 2 Type II | Audit in progress — interim letter available under NDA | In progress |
| ISO 27001 | Certification in progress — current scope available under NDA | In progress |
| HIPAA BAA | Business Associate Agreements for healthcare customers | Enterprise |
| GDPR & CCPA | DPA signed — data subject rights fully honored | All Plans |
| Identity & Access |
| SAML 2.0 SSO | Okta, Azure AD / Entra ID, Google Workspace, OneLogin | Enterprise |
| SCIM 2.0 Provisioning | Automated user and group lifecycle from your IdP | Enterprise |
| Fine-grained RBAC | Control access to repos, models, and agent capabilities per role | Enterprise |
| Audit Logs → SIEM | Streaming to Splunk, Datadog, Sumo Logic, Elastic via webhook or S3 | Enterprise |
| Session & Device Policy | IP allow-listing, session timeouts, enforced MFA | Enterprise |
| Deployment & Data Residency |
| Dedicated GPU Pool | Reserved GPU capacity for your models — no shared inference, no rate-limit contention | Enterprise |
| Single-tenant Sandboxes | Per-workspace isolated execution for agents, code runs, and tools | Enterprise |
| Multi-tenant SaaS | Fastest path to production on our hardened cloud | All Plans |
| Dedicated VPC | Single-tenant cloud deployment in AWS / Azure / GCP | Enterprise |
| On-Premise | Deploy inside your own datacenter with our install package | Enterprise |
| Air-gapped | No outbound internet required — fully sovereign install | Enterprise |
| Regional Residency | Pin to US or EU regions — data never leaves the region | Enterprise |
| Customer-managed Keys | BYOK / CMK for full cryptographic control | Enterprise |
| Models & Integrations |
| Frontier + OSS Models | Claude, GPT, Gemini, Grok, Llama, Mistral, DeepSeek, Qwen — one key, every model, automatic failover | All Plans |
| BYO Model Endpoints | Route to private models on your preferred hyperscaler or any OpenAI-compatible endpoint you host | Enterprise |
| Self-hosted Git | GitHub Enterprise Server, GitLab Self-Managed, Bitbucket Data Center | Enterprise |
| Custom Integrations | Jira, Slack, Teams, Linear, and custom webhooks | Enterprise |
| Unified API | OpenAI-compatible — one key across every model | All Plans |
| Governance & Admin |
| Workspace Isolation | Per-tenant encryption keys, no cross-tenant access | Enterprise |
| Usage Quotas | Per-user and per-team spend limits with real-time alerts | Enterprise |
| Model Allow-listing | Restrict which models can be used per team or project | Enterprise |
| Content Policy Controls | Custom DLP rules, prompt filters, and redaction policies | Enterprise |
| Admin Dashboards | Usage, spend, and activity across every workspace | Enterprise |
| Support & SLA |
| 99.9% Uptime SLA | Contractual uptime guarantee with service credits | Enterprise |
| 24/7 Priority Support | Response times as fast as 4 hours for critical incidents | Enterprise |
| Dedicated CSM | A named Customer Success Manager assigned to your account | Enterprise |
| Named Slack Channel | Shared Slack or Teams channel with our engineering team | Enterprise |
| Custom Onboarding | White-glove rollout, training, and SSO / deployment setup | Enterprise |