Trust you caninspect.
Found a security issue? Tell us
01 · 9 controls
AI safety
The model works inside rules it can't break.
- catalogdairytree_nutsnew runtree_nutsdairy
Merged, not replaced. Dairy stays.
Live demo · A new run can't drop an allergen Outputs validated against fixed contracts
Every AI result is checked against the values the contract allows. Anything off-list is dropped instead of stored.
Read how it worksUnknown is never served as safe
When a caller excludes a value, a record comes back only if it is known not to have it. A record nobody has decided is left out, even though nothing says it is unsafe.
Read how it worksSafety rules enforced outside the model
Exclusions are part of the query the agent's tool runs, so no prompt can talk a model out of them. Zabber uses the same rule to keep injury exclusions out of generated plans.
Read how it worksSafety values can only be added
On a safety field a run can add a value but never quietly remove one. A removal waits for a person, and the receipt names who approved it.
Read how it worksAn unsure answer is never served as safe
Below a field's confidence threshold, nothing is stored without a person. A safety field can be set to show the possible value at once, marked flagged, but it still counts as unknown until someone confirms, so the record stays out of any exclusion.
Every value carries a receipt
Rule or model, the confidence, the contract version and who approved it, returned with every record an agent calls for.
Read how it worksEvery fact quotes its source
A value read out of a record, such as a weight, a date or an ID, is stored only if the exact words it came from are found in that record or document and really say that value. A quote that isn't there sends the value to a person instead.
Accuracy checked before anything is published
With an answer key of values a person confirmed, a new release is measured before it goes out. If it would find a safety value less often than the last release did, publishing is refused unless a person gives a reason, and the release keeps that reason.
A broader tag is never taken as safe
When a caller excludes cashew, a record tagged only "tree nuts" is left out too: it isn't known to be free of cashew. Excluding "tree nuts" leaves out every nut under it.
02 · 10 controls
Data protection
Data, keys and connections kept apart, encrypted and checked.
select * from records
- Paneer tikkayour workspace
- Lamb rogan josh other workspace
- Dal makhaniyour workspace
- Fish curry other workspace
2 rows. No filter in the query, and still only yours.
Live demo · Each workspace sealed off in the database Third-party credentials encrypted at rest
A connection to your own database is stored with AES-256-GCM, decrypted only inside the request that dials with it, and never returned by any endpoint. The same holds for integration credentials in the products we have shipped for clients.
A connection can only reach outward
A connection string you give us is a request we make on your behalf, so every address it resolves to is checked first: loopback, link-local and private ranges are refused, which is what stops one being pointed at our own cloud metadata.
A database has to prove which one it is
A connection uses TLS and the certificate is verified, hostname included, so an address that answers in place of yours is refused rather than handed your password. A database using a certificate you issued yourself can be trusted explicitly, per connection, and says so wherever it is listed.
Each workspace sealed off in the database
Every table that holds a workspace's data has row-level security, enforced even for the table's owner. A query that forgot its workspace filter still can't see another workspace's rows.
Your own model's key stays where you put it
A workspace's own model credential is encrypted with AES-256-GCM, never returned, and only ever sent to the address it was saved for. An address on a private or internal network is refused.
Roles enforced in one place
Owners, builders and reviewers. A reviewer can only make the writes on an allow-list, such as resolving the review queue, so a new kind of write is closed to reviewers until it is added. A workspace always keeps at least one owner.
Webhooks are signed, and only reach outward
Every delivery is signed with a secret shown once and stored encrypted, so a receiver can tell it came from us and wasn't replayed. A webhook must use https and a public address, checked again at every send; redirects are refused, and deliveries carry ids and numbers, never record data.
Hand edits are locked
A value a person sets by hand is locked against later runs, so an automated pass never overwrites a decision someone made.
Redacted structured logging
Logs are structured, carry the request and workspace they belong to, and redact sensitive fields before they're written.
The playground keeps nothing you type
A description typed into the playground builds a sample and isn't stored: the sample is cached under a hash of it, never the text.
03 · 4 controls
Reliability
Runs that survive interruption and skip work already done.
Runs that survive interruption
A run is split into batches on a job queue that retries with backoff and never processes the same batch twice at once. Records already done are kept.
No needless reprocessing
A record a run already decided, with the same input, is skipped instead of being sent to a model again.
A release must pass the tool's scenarios
A tool can carry scenarios: searches it must keep answering right, such as nut-free never returning a dish with cashew. A new release reaches the tool only once it passes them all; one that fails is held back, the tool keeps serving the last release that passed, and the owners are told.
Drift caught before it's published
A scheduled sync compares the new version with the last release. A safety value on fewer records, or more records unknown, holds it for a person. Publishing automatically is off unless an owner turns it on.
04 · 3 controls
Engineering
Every change tested, every request and AI call traceable.
CI on every change
Formatting, lint, type checks, every package's tests against real Postgres, MySQL and MongoDB, the production builds, a secret scan and a dependency audit run on every change.
Every request traceable
Every response carries a request ID, every error shows it, and every log line for that request carries it too, including the background jobs it started.
Every AI call is accounted for
Each call to our model spends one of the workspace's starter credits, and each receipt names the model that answered. Calls to a workspace's own model are named but not counted.
05 · 6 controls
In client products
From Zabber and Gobbles, the products we built before CloudCrane.
19 / 19 agent scenarios passing
Live demo · Agents checked against scripted scenarios Conservative extraction
When the model is unsure whether an allergen is present, it's included. Missing one is worse than over-warning.
Safety data kept out of similarity search
Allergens are excluded from embeddings so a "dairy-free" search can't match a dairy dish on wording alone.
Read how it worksAgents tested with scripted scenarios
Agent behaviour is checked against 19 scripted scenarios, and retrieval quality has its own evaluation harness.
Read how it worksVerified, idempotent webhooks
Incoming webhooks are signature-checked, duplicates are ignored, and delivery statuses can only move forward.
Opt-outs honoured twice
Marketing opt-outs are removed when an audience is built and checked again at send time, including Hindi opt-out phrases.
2,000+ automated tests
Unit, integration and mobile tests across Zabber and Gobbles, with integration tests run against a throwaway database.
Before you ask
Still have a question? Tell us