Governed by design

TensorLot never owns your documents — it reads them where they live, with the permissions you already have, and serves the cleaned knowledge back with citations. Governance is built into the product, not bolted on: every agent has a scope, an owner and an audit trail.

At a glance
Hosting
EU · private cloud on request
Source access
read-only, permission-aware
Encryption
in transit & at rest
Agents
scope · owner · audit log

controlsWhat protects your knowledge.

Data protection

  • Encryption in transit (TLS) and at rest
  • Your sources stay where they are — TensorLot reads, it does not migrate
  • Tenant isolation: one tenant, one index, one key space
  • EU hosting; private cloud / customer VPC on request

Access control

  • Sign-in through your Microsoft 365 identity (SSO)
  • Read-only connectors scoped per tenant and site collection
  • Role-based access to the console
  • Knowledge spaces define what people and agents can see

Agents & MCP

  • Default-deny tool list per agent
  • Bound scope and an accountable owner for every agent
  • Keys expire; revoke in one click
  • Dry-run playground before anything goes live

Monitoring & audit

  • Every agent call logged with agent, tenant and tool
  • Document actions recorded with outcome (resolved, archived, moved, ignored)
  • Denied calls are logged too
  • Exportable on request for your compliance reviews

agentsAn agent never sees more than the human behind it.

Agents are first-class citizens of the governance model, not an exception to it. Scope, owner, expiring keys and a full audit trail come with every MCP endpoint.

  • Scope: sites, libraries or topics — nothing else
  • Owner: a named person accountable for every call
  • Actions: explicit, rule-based, handed to the user’s rights — TensorLot never writes to SharePoint itself
  • Audit: agent · tenant · tool · outcome, for every call

complianceHonest about where we stand.

We are a young company building for regulated enterprises. This is the current status — we would rather tell you what is in preparation than print a badge.

By design
GDPR

EU hosting, data processing agreement, read-only access to your sources, deletion on request.

In preparation
SOC 2

Controls and evidence collection under way; audit planned. Ask us for the current control list.

In preparation
ISO 27001

Information security management system being documented alongside SOC 2.

On request
Customer reviews

Security questionnaires, architecture walkthroughs and customer-specific reviews for enterprise deployments.

next stepNeed the details?

We walk your security team through the architecture, the connector permissions and the agent governance model — and share the current control list.