Security

Trust is the product.

Most AI security is a promise about filtering. SweetHive's is a property of the data model: content that was never visible to you can never reach your AI, because scope is decided at write time, not query time.

Scope is structural

The permission tree and the AI's reach are one object.

There is no separate filter to misconfigure. What a person (or their agent) can retrieve is exactly what their groups can see, from their level of the context tree down. Guarantees that follow from the model, not from policy:

Decided at write time

Every message, file and note enters a context addressed to groups. Visibility is set when content is created, never cleaned up afterwards and never inferred at query time.

Per-context audit

Every AI answer is traceable to the exact items it was allowed to read. You can show, for any response, why each source was in scope.

Agents stay inside boundaries

Agents inherit the context they're installed in and see only what its groups see. Nothing crosses the tree without an explicit share.

Runs where your data lives

The agent comes to the data; the data never comes to the agent.

Scope isn't only a software boundary. Organizations with private nodes can pin sensitive processing and agents to their own hardware, so scoped work runs inside the institution and data never leaves. Heavy, non-sensitive workloads burst to a distributed network for elasticity and cost. An orchestrator routes every workload by sensitivity, latency and cost; you set the policy per agent.

Context workload SCOPED AGENT / JOB Orchestrator SENSITIVITY · LATENCY · COST Private nodes ON-PREM · DATA STAYS Distributed network ELASTIC · LOWER COST

Private nodes: sovereignty

Sensitive, context-bound work is pinned to the institution's own machines. Scope is enforced down to the hardware; data residency stays under your control.

Distributed network: elasticity

Anonymous heavy compute (indexing, transcription, large-scale processing) bursts to the network. Unit cost falls as capacity grows.

You set the policy

Per agent: automatic (orchestrator decides), private only, or public allowed. The default keeps sensitive work at home.

Compliance & data

Built for regulated, high-trust environments.

The blocker for AI in museums, schools and regulated businesses is always the same question: where does the data go? SweetHive's answer is structural, which is why it can be deployed where assistants bolted onto flat channels cannot.

  • Scoping enforced structurally: the permission tree and the retrieval boundary are one object.
  • Per-context audit: every AI answer is traceable to the items it was allowed to read.
  • EU-hosted, with data residency in the EU.
  • Encrypted in transit and at rest; payments via Stripe: no card data ever touches our servers.
  • Agents can be pinned to on-prem private nodes, with scope enforced down to the hardware.
  • Agents run inside context boundaries; nothing crosses the tree without a share.
Infrastructure

Hosted in the EU, private by default.

EU infrastructure

SweetHive runs on AWS in the eu-west-1 region (Ireland). Data at rest lives in the EU, with automated backups and point-in-time recovery.

Encryption and payments

Traffic is encrypted in transit and data is encrypted at rest. Payments run on Stripe; card data never touches our servers.

Local inference option

With SweetHive Agents Node and Agents Server, AI models can run on your own hardware: prompts and data stay inside your perimeter during inference.

Subprocessors

Who processes what.

Amazon Web ServicesCloud infrastructure, storage and backups (eu-west-1, Ireland).
StripePayment processing and billing; card data never reaches SweetHive.
Google FirebaseInfrastructure for the support chat widget.
Google Analytics 4Aggregate usage statistics, only after cookie consent.
Google FontsWeb font delivery.
The list reflects the current platform and may evolve with the product.
Your data

Retention, rights and AI conduct.

Retention

Account data and content are kept for as long as the account exists. If you delete your account, personal data is deleted or anonymized within technical backup cycles.

Your GDPR rights

Access, rectification, erasure and portability are described in the privacy policy. Data protection officer: dpo@sweethive.com.

AI conduct

Every agent answer is attributable to the items it was allowed to read, publishing always requires explicit human confirmation, and AI output is always labeled.

Contact

Questions or concerns?

Found a security issue, or need details these pages don't cover? Write to us and we'll route it to the right person.

See scoping you can audit.

One question, three personas, three correctly-scoped answers from the same hive, each traceable to exactly what it was allowed to read.

Get a demo