Modly

Security & Trust

Trust is the missing layer in AI

Modly respects each person's permissions, cites its sources, and logs every query, with the same governance for every customer.

Trust

Why trust is a security concern

Security reviewers usually start with SSO, MFA, and audit logs. Those matter. But in AI, trust is a security concern before the controls kick in.

An AI system that produces confident answers without showing its work is a security problem the same way an admin action without an audit trail is. Both invite decisions that can't be verified, challenged, or rolled back.

Modly is built so every answer can be traced. Every response cites the exact documents it drew from. Every retrieval only reaches sources the asker is already allowed to see, access is resolved from your existing providers, not assumed. Every query is logged with the sources it used, so "what did AI tell whom" is a database query, not a forensics exercise.

The controls below are the enforcement layer. This is the design principle underneath them.

Read the full argument: Why Enterprise AI Fails Without Trust →

Security features

Built with trust as the starting point

Permission-aware retrieval

Stale, missing or expired provider access is treated as zero access.

Cited sources

Every answer links back to the exact document it drew from.

Full audit logs

Every query and answer is recorded and reviewable.

Org-level model policy

Control which models are allowed and default across the organization.

MFA & access controls

TOTP MFA and password management backed by Cognito.

Organization isolation

Each organization's data stays completely isolated from every other.

How we handle your data

Your knowledge stays yours

  1. 1

    Least-privilege by default

    Retrieval only ever reaches sources the asker is already allowed to see. Access is resolved from your providers, not assumed, and re-checked as it changes.

  2. 2

    Not used to train models

    Your content is indexed to answer your team's questions, it isn't used to train shared models, and it never leaves your organization's boundary.

  3. 3

    You choose the model

    Route through OpenAI, Google, Anthropic or a self-hosted model, and set the allowed models per organization. Sensitive workloads can stay on infrastructure you control.

Controls & compliance

Built for teams that answer to auditors

Authentication, access controls and a complete activity trail, the same for every customer, with no governance features locked behind a higher tier.

Authentication & MFA

SSO and TOTP multi-factor authentication, with password and session controls.

Complete audit trail

Every query, answer and configuration change is recorded and reviewable.

SOC 2 Type II

On our security roadmap as we move toward general availability.

See Modly on your own knowledge

Request a demo, or join the waitlist for early access.