Skip to main content
Security Datasheet

Enterprise-Grade Security
for Knowledge Transfer

Exit Insights processes sensitive employee data with encryption, automated PII detection, compliance annotations, and human-in-the-loop checkpoints at every stage.

75

PII patterns detected

Identified and flagged for review

5

HITL checkpoints

Human approval before extraction, analysis, generation and release

AES-256-GCM

Connector token encryption

Platform encryption at rest for files and data

None

Data received by us

With the Claude Code skill or self-hosting

Security Controls

Six layers of security protect your organization's sensitive knowledge transfer data.

🔒

Data Encryption

Data is encrypted in transit by the platform and at rest by the storage providers; the credentials we hold for you are encrypted by us.

  • Third-party connector tokens (Google, Microsoft, Slack, GitHub, Notion, Confluence) are encrypted with AES-256-GCM before they are stored
  • Uploaded artifacts and generated documents are stored on Vercel Blob and Neon Postgres, which encrypt at rest — not under an application key of ours
  • All traffic is served over HTTPS terminated by the hosting platform
🛡️

PII Detection

75 PII patterns identified and flagged before document generation.

  • 75 PII patterns including SSN, credit cards, phone numbers, addresses, and medical IDs
  • Regex + contextual analysis for high-precision detection
  • Findings are flagged for the reviewer; the finished documents are re-scanned for credential leaks before release
  • PII findings surfaced in the Security Review document for human review
📋

Compliance Annotations

Framework-specific compliance markers throughout generated documents.

  • GDPR — data subject rights, processing basis, retention requirements
  • HIPAA — PHI identification, minimum necessary principle
  • SOX — financial data controls, audit trail, access documentation
  • CCPA, FERPA, PCI-DSS — additional framework annotations as applicable
👤

Human-in-the-Loop Checkpoints

Five review gates stop the run until a person approves — the fourth only for voluntary departures.

  • Gate 0: Corpus survey — see what will be read and what was set aside, and restore any class of file, before anything is extracted
  • Gate 1: Scope review — confirm which sources and files will be analyzed
  • Gate 2: Security review — every PII and credential finding, worst first, before document generation
  • Gate 3: Employee validation — for voluntary departures, the departing person can confirm what was attributed to them (optional)
  • Gate 4: Package review — approve the complete package before distribution; it is re-scanned for credential leaks first
🏢

Self-Hosted Deployment

Enterprise tier includes fully self-hosted deployment — your data stays on your infrastructure, and the one model call runs under your own Anthropic key.

  • Docker-based deployment for on-premises or private cloud
  • Bring your own LLM API key for hosted plans — planned, not yet available
  • No data transmitted to Exit Insights servers in self-hosted mode
  • Also available as a Claude Code skill that runs on your own infrastructure — Exit Insights never receives your data

Operational Controls

What is in place today, stated plainly. Exit Insights is not SOC 2 certified.

  • Access controls — role-based permissions (ADMIN, HR, MANAGER, IT) and HttpOnly session cookies
  • Audit logging — logins, registrations, report creation, download and sharing, purges, and user and organization changes are written to an audit log
  • Change management — version-controlled infrastructure, CI on every push, automated deployments
  • Monitoring and retention — a 30-minute production health check that opens an issue on failure; uploads purged after 24 hours, reports after 30 days

Data Flow & Controls

Every step of the knowledge transfer process includes security controls and human oversight.

1

Upload

Artifacts travel over HTTPS and are stored on encrypted platform storage. File type validation prevents malicious uploads.

2

Scan

PII detection engine scans all artifacts. 75 PII patterns flagged. Credentials and secrets identified.

3

Review

HITL checkpoint — human reviews flagged content, approves scope, and authorizes document generation.

4

Generate

Documents generated with compliance annotations, then re-scanned for credential leaks and held for your review before release.

Need a Custom Security Review?

Enterprise customers receive a dedicated security review, custom compliance configuration, and self-hosted deployment support. Contact us to discuss your requirements.