Trust
Data security
How the content you connect and the conversations people have with your assistant are handled, and where the boundaries are.
Solandra processes the content you connect and the conversations people have with your assistant. These are the controls and boundaries to understand before using it.
Project access and roles
Dashboard access requires sign-in. Protected service requests verify the session and check project membership. Roles control who can manage sources and widgets, review gaps, assign team access, and delete resources.
Knowledge retrieval is scoped to a project. Separate projects are the way to keep distinct knowledge bases apart.
Public and private source visibility
Public widgets retrieve from sources marked public. Private sources are excluded from public answers; authenticated internal requests can use both public and private sources when authorized for the project.
All public widgets in one project share its public source set. Making a source private does not protect its original website URL or retract content already shared in an earlier conversation.
Authentication and browser protections
Solandra uses Supabase Auth for account authentication. The dashboard stores its access token in an HTTP-only cookie so browser scripts cannot read that cookie through the normal document-cookie interface.
The dashboard includes browser headers that prevent framing and restrict selected browser capabilities. Public widgets support an allowed-origin setting that restricts where browsers can embed the widget when configured.
The public widget key identifies an assistant; it is not a secret or proof of a visitor's identity. An embedding restriction does not make a public assistant or its API private.
Controls around requests and AI input
The service applies request limits and daily widget caps to help limit abuse and excessive use. Selected sensitive fields are redacted from application logs.
Answer generation is instructed to use retrieved source content and to identify insufficient evidence. Retrieved page text is treated as reference material rather than trusted instructions. These measures reduce some risks; they do not guarantee perfect answers or eliminate every prompt-based attack.
Service providers and AI processing
Operating the assistant involves providers for crawling, authentication, storage, AI, hosting, and email. Relevant source text, questions, and conversation context may be sent to the AI provider. Private source visibility does not prevent service-provider processing.
Review subprocessors and processing locations
Hosting and operational safeguards
Solandra runs on managed providers, each with its own security programme: Supabase (Pro plan) for authentication and the database, Qdrant Cloud for the search index, Railway for the applications, Resend for email and OpenAI for AI. All traffic uses HTTPS. Data is encrypted at rest by those providers. The database is backed up daily by Supabase. Administrative access to every provider is held by the founder alone and protected with two-factor authentication. Application logs redact tokens and secrets. Security reports go to contact@solandra.io and are answered by the founder directly.
Your team's part
- Connect content you are authorized to use and review what is marked public.
- Give project access only to the people who need it.
- Keep passwords and API secrets out of website content and conversations.
- Check important answers against the underlying sources.
- Contact us before using the service for information with special handling requirements.
Data removal and retention
Pausing or making a source private affects its use in answers after the change is applied. It does not erase earlier conversations. Starting a new conversation changes the visitor's current conversation; it is not a deletion request.
Retention and deletion practices are described in the Privacy policy. Contact contact@solandra.io for a data request.
Report a security issue
Email contact@solandra.io with a description of the issue and the smallest set of steps needed to understand it. Please avoid accessing, changing, or including another person's data in a report.
If you have specific security requirements, talk with the founder before connecting content.