Security & trust
Safe to connect to your tools.
Praxeum is a knowledge and control plane, not an execution proxy. We read what you scope, we prove where every skill came from, and a human is accountable for everything an agent can do.
The short version
What’s accessed
Only the sources you connect (Slack, Google Workspace, Notion), over read-only OAuth, scoped to the channels, folders, and spaces you pick. We never hold write credentials to your systems.
What’s stored
The exhaust we mine, the episodes we assemble, and the skill artifacts, each cited back to the exact source thread. PII and secrets are redacted at ingestion before text can enter a draft.
How it’s used
Mined into skill candidates only. Nothing an agent can run exists until a named human on your side approves it. Mined text is treated as untrusted data, never as instructions.
Who’s accountable
Every skill carries a named approver, a version, and a replayable audit trail, so you can always answer "under whose authority." Full purge on request, per-tenant isolation underneath.
How we earn access
Six controls, one principle: least privilege.
Read-only, and scoped by you
Every source connection uses read-only OAuth, limited to the specific Slack channels, Drive folders, and Notion spaces you select, with more sources on the way (each read-only, each scoped). We never hold write credentials to your execution systems; your agents use their own.
Permissions travel with knowledge
A skill drafted from a private channel inherits those permissions through every layer. Broadening visibility requires an explicit, audited human action.
Redaction at ingestion
PII and secrets are scrubbed before text can enter a draft or a trace: a pasted API key never reaches a skill or any answer.
Human approval is the firewall
All mined text is treated as untrusted data, never as instructions. Nothing an agent can execute exists until a person approves it.
An audit trail you can replay
Immutable versions, pinned evidence, approver identity, and point-in-time replay answer "your AI issued a refund, under whose authority?" It’s a detective control over reported agent behavior; we say so plainly rather than overclaiming enforcement.
Tenant isolation & offboarding
Per-tenant isolation with row-level security as defense-in-depth, and a full purge path on request: deletion propagates to documents, embeddings, and connections.
Google Workspace access
Read-only scopes, limited to what you choose.
We use these solely to convert your documented and observed procedures into verified skills for your own team, in line with the Google API Services User Data Policy (Limited Use). Full detail is in our Privacy Policy.
drive.readonlyRead documents in the shared drives and folders you explicitly select, to convert procedure-shaped docs into cited draft skills.
drive.meet.readonlyRead Google Meet transcripts for the recurring meeting series an organizer chooses to include.
The people we mine
Built for the people whose knowledge we mine.
Mined knowledge names its owner as author of record. Scoping is employee-visible. We never produce individual performance analytics. Your process gets your name on it.
Subprocessors
A short, disclosable list.
We keep the list short and disclosable, prefer SOC 2 vendors, and know which can be self-hosted. Design partners receive the current list and a DPIA template on request.