Labels only add protection.
The engine can mark a document as more sensitive, never less. Access is still decided by the system that owns the file, so a wrong label can never expose anything.

Everything runs inside your instance. No document, query or label is sent to Listening Post or to an outside model provider.
Discuss a security review
Listening Post has completed SOC 2 Type II. Bring your security team into the conversation and discuss the report with us.
Ask about the reportThe engine can mark a document as more sensitive, never less. Access is still decided by the system that owns the file, so a wrong label can never expose anything.
Permissions are checked before an answer is built. A file someone cannot open never shapes what they are told.
Ask why a document was marked confidential and get a real answer: what decided it and how sure it was. Your team can audit it instead of trusting it.
Every tool signs in as the person asking and sees only what they could already open in Google, Microsoft, Slack, GitHub or QuickBooks. An assistant has no access of its own to abuse.
Everything runs on your hardware. Nothing goes to Listening Post or to a model provider, and your network team can confirm it from your own firewall logs.
Your VPC with your own keys, an isolated environment we run, or your own building behind an air gap. Same product, same guarantees, and you can move later without starting over.
The engine keeps two separate things: what your company knows, and what each person is working on. The second is why answers improve with use. It is also a record of what every employee asked, which is a surveillance system waiting for someone to abuse it. We built it so nobody can, including us.
| Who | Can see | Cannot see |
|---|---|---|
| The person | Their own questions, history and working context | Anyone else’s |
| Their manager | Nothing | What they asked or opened |
| Company administrator | Usage volume, system health, which documents are retrieved often, gaps where questions went unanswered | Who asked what |
| Listening Post | System health on hosted instances | Any personal context, any document |
Personal context is locked to its owner inside the query, the same layer that enforces document permissions. An administrator cannot grant themselves access because the capability to read someone else’s context was never built. It is the same mechanism that keeps our own support team out of your content.
Administrators need to know where people are asking questions the company cannot answer, and they get that. What they cannot do is narrow a report down to one person. A question asked by a single individual never appears in an aggregate, so filtering until one name is left produces nothing.
Your working context persists because it is yours. Anonymous totals persist because they are anonymous. The record joining a name to a specific question is the one that would make surveillance possible, and it is the one that does not last.
Anyone can switch personal context off for themselves without asking, and company search works exactly as well as before. Deleting it removes it. There is no hidden flag.
We will work through the report, your environment, and the hard questions about where your data goes.