Security at Scormy One
Scormy One is designed to handle source materials responsibly across storage, access, and processing. Our security posture is shaped around customer data boundaries, backend enforcement, and source-grounded generation.
Model
A source-grounded training engine, not an unconstrained content generator.
Boundary
Tenant-scoped data handling with explicit ownership and access context.
Enforcement
Security relies on backend controls, not frontend-only gating.
Built with a security-minded architecture direction
For teams handling operational and internal documentation, these principles shape how the platform is designed and reviewed.
Customer-owned source material
Least privilege by default
Defense in depth
Secure-by-default direction
Clear trust boundaries
Security as a design property
Explicit, bounded, tenant-scoped data flows
Uploaded source materials, extracted knowledge, and generated artifacts move through controlled processing and storage paths. Scormy One uses source content to produce grounded outputs — it does not treat customer materials as an open, public corpus.
High-level flow
- 1Source files enter controlled ingestion and validation paths.
- 2Extraction and transformation occur within bounded backend workflows.
- 3Derived outputs remain associated with tenant-level authorization.
- 4Source, knowledge, and generated artifacts are logically separated where needed.
Authorization mapped to tenant, role, and identity
Tenant-scoped authorization
Access decisions map to tenant membership, role context, and authenticated API identity.
Backend policy enforcement
Separation between data ownership, access rights, and commercial boundaries is enforced in backend systems rather than client state.
Authenticated API surface
API access requires authenticated and authorized requests, with explicit scope checks for sensitive operations.
Tenant-aware processing
Multi-tenant boundaries are treated as core trust limits across ingestion, generation, and artifact lifecycle.
SOC 2 Type II compliance is available on the Enterprise plan.
Safety through source-grounded generation
Scormy One transforms customer-provided source material into structured training outputs. It is not intended to generate unconstrained narrative content detached from operational evidence.
The generation model follows a practical rule: duration is a constraint, not a content source. If source support is thin, the safer behavior is compression, explicit gaps, or reviewer-requested expansion — not unsupported padding. This source-bounded approach reduces classes of quality and trust risk common to generic AI generation.
Operator note: generated outputs should be reviewed and approved by domain owners before operational rollout, compliance use, or external distribution.
Controls across the lifecycle
Auditability direction
Controlled generation flow
Review before publish
Bounded mutations
Monitored operations
Deliberate change control
Common evaluation questions
Responsible disclosure
If you identify a potential security issue or need security-related support, contact us with reproducible details. We review reports and prioritize responsible handling.
Training your team can stand behind
Source-grounded by design, reviewable before publish, and scoped to your tenant.
15-day Growth-tier trial · $10 in AI credit · no card to start.