Security
You can see exactly what it can reach.
And take it back.
Not a setting we promise to honour. Arithmetic you can check.
This page is the detail behind that claim — how identity works, how authority is scoped, what is recorded, where your data physically sits, and what we have not yet earned the right to claim.
Identity
There is no password to steal
Altimist ID is passkey-first. Sign-in is a WebAuthn ceremony against a key that never leaves your device, so there is no shared secret in a database for anyone — including us — to lose.
Passkeys, not passwords
Face ID, Touch ID or a hardware key. Your biometrics stay on the device; what reaches us is a signature, and a signature is useless anywhere else.
Phishing-resistant by construction
A passkey is bound to the origin it was created for. A convincing copy of our sign-in page cannot borrow it, because the browser will not offer it.
One identity, every surface
Mac, iOS, web and the API all resolve to the same Altimist ID, so revoking a device revokes it everywhere at once.
Enterprise sign-in
SSO and SCIM on Business and above, so joining and leaving are driven by your directory rather than by someone remembering.
Authority
Grants are scoped, timed and revocable
A conventional plug-in runs as you: everything you can see, for as long as it exists, with no record. An Altimist grant names the objects, sets an expiry and can be withdrawn in a single action — and the document itself shows you who holds one.
- 01
Named objects, not blanket access. A grant lists what it covers. There is no “all files” scope to tick by accident.
- 02
An expiry by default. Until Friday, until the project closes, or until you say otherwise — grants are expected to end.
- 03
Visible from the object. Open a document and see every party that can open it — including whether that is us.
- 04
Revocation is one action. Not a support ticket, not a 24-hour propagation window, and not a promise.
- 05
Encryption follows the grant. Objects are encrypted per grant, so withdrawing one removes the ability to decrypt rather than merely hiding a button.
Image placeholder
The architecture, drawn once and drawn properly — the diagram a sceptical CISO or technical partner arrives looking for. Show the hub-mediated topology: parties (person, agent, counterparty organisation) each with a handle and key; the object store in the middle; grants as scoped, dated edges; the op-log as an append-only spine beneath. Label what the hub can and cannot read. Brand navy and sand, theme-aware, no gradients or 3D.
16:9 · SVG (theme-aware) · must remain legible at 1000px wide
Accountability
Everything that happened, and who did it
The op-log is not a logging feature that can be switched off. It is the mechanism the product runs on: an operation is how anything changes, and an operation is signed as it is applied.
Signed
Each operation carries the key of the party that made it — human or agent — and the grant it acted under.
Reversible
Because the operation is the unit rather than the file, undoing it is exact rather than a restore from a backup.
Exportable
Continuous audit export on Business and above, in a form your auditors can read without asking us to interpret it.
Data
Where it sits, and who can compute on it
Encrypted in transit and at rest
TLS 1.3 on every hop, AES-256 at rest, and envelope encryption keyed to the grants above rather than to one master key held somewhere convenient.
Two tiers, chosen per object
Public Edge for work that should be fast and shareable; Private Vault for work the host must not be able to read. You pick, per object, and the interface tells you which you are in.
Isolated tenant compute
On Business, your Org Brain and its index run on compute nobody else shares. On Sovereign, on hardware you designate — your building, or a dedicated tenant on ours.
Zero Data Retention at the model layer
Nothing in your corpus trains anything, on any plan. On Business and above, prompts and completions are not retained by the model provider at all.
Residency
UK and EU regions available, with Sovereign deployments pinned to a location you name. Egress is free — reading your own data has never cost anything.
Leaving
Export the whole corpus and the whole op-log, in open formats, without asking. A product you cannot leave is a product you cannot safely join.
Assurance
What we hold, and what we do not
We would rather tell you a certification is in progress than let a badge imply one that has not been audited.
Responsible disclosure
Found something? Tell us before you tell anyone else.
Write to security@altimist.com. We acknowledge within two working days, keep you updated while we fix it, and credit you when it is closed unless you would rather we did not.
Safe harbour
Report in good faith, stay within the scope below, avoid privacy violations and service degradation, and give us reasonable time to fix it — and we will not pursue or support any action against you.
In scope
altimist.com, altimist.ai, altimist.id, the API, and the Mac and iOS clients. Authentication, authorisation, grant enforcement and op-log integrity are the findings we care most about.
Out of scope
Denial of service, social engineering of our people, physical attacks, spam or rate-limit findings without impact, and reports generated by a scanner with no demonstrated exploit.
What helps
A reproduction, the affected handle or object, and the operation ID if one exists. Encrypted mail is welcome — ask for the key at the same address.
Send it to the people who will read it properly.
Procurement questionnaires, DPAs, penetration-test letters and architecture reviews all go through the same address.