Security & Trust Brief · for finance leaders

Your records stay yours — and we can prove it.

Finance data is the most sensitive memory an AI can hold. 9scroll is built so the honest answer to “who can see my records?” is a short one — and one you can watch us demonstrate, not just assert.

In sovereign mode you hold the key and we store only ciphertext we cannot read. So “exposed to whom?” has a clean answer: no one — including us.

Your concern → our control → the proof

A finance buyer converts on demonstration, not adjectives. Every control below is something we can show you live.

I don't want my records exposed — not even to the vendor.
ControlZero-knowledge (customer-held key). Encryption happens on your machine; the key never leaves it. We store double-wrapped ciphertext we have no way to open. ProofTry the live browser demo: type a secret, watch it seal, then fail to open it with the wrong key. Same math, at scale, in sovereign mode.
What if your database is breached or subpoenaed?
ControlEncrypted at rest, per record (XChaCha20-Poly1305, a fresh nonce every write). A stolen database or leaked backup is unreadable noise. ProofIn a live session we dump the raw database row on screen — it's ciphertext. A subpoena of our storage yields nothing readable.
Can another client — or another AI — see my data?
ControlHard tenant isolation. Every read, list, and route is scoped to your namespace. No cross-tenant traversal. ProofOur live two-tenant test: Tenant A literally cannot list or read Tenant B — on screen, even trying. Isolation shown, not claimed.
Can you prove who changed a record, and when?
ControlSigned, timestamped, tamper-evident. Every record carries a cryptographic signature and a server-anchored time — a built-in, immutable audit trail. ProofA controls/SOX story as much as a security one: you can prove authorship and integrity, and detect any alteration.

The reviewer checklist — with the honest gaps

A CFO trusts a vendor who shows the ❌s and the dates more than one who claims all ✓. Here is exactly where we stand.

ControlTodayOn the roadmap
Encryption at rest✓ XChaCha20-Poly1305
Encryption in transit✓ TLSdocumented
Zero-knowledge / customer-held key✓ sovereign bridgeself-serve setup
Tenant isolation✓ proven by test+ third-party pen test
Access control within your org◐ tenant-levelper-path roles & ACLs
Right to erasure / retention○ in progressdelete & forget (near-term)
Immutable audit trail✓ signed & timestampedone-click signed export
DPA · breach SLA · data residency◐ EU (Frankfurt)contractual pack
SOC 2 Type II / ISO 27001○ plannedreadiness underway

We'd rather earn the deal by showing you the roadmap than lose your trust by overclaiming. Every item above is dated in our internal plan; ask and we'll walk you through it.

See the isolation test live.

Ten minutes, on a screen share: we provision two tenants in front of you and prove one cannot touch the other. No slides.

Request a security demo →