SECURITY ยท LAST UPDATED 2 SEPTEMBER 2026

Security at CONSELA

CONSELA is designed to protect the workspace data needed to provide its research and advisory features. This page summarizes our current security practices. It is an overview, not a guarantee that every risk can be eliminated.

Hosting and access

  • Application and database infrastructure runs on EU-region hosting.
  • Organizations and projects use tenant-scoped authorization and role-based access controls.
  • Administrative and background operations are separated from user workspace access.
  • Authentication protections include password controls, anti-forgery checks, rate limiting and security logging.

Encryption

  • Connections use HTTPS/TLS in transit.
  • Project files, extracted-text sidecars, meeting documents and backup archives are encrypted at rest.
  • Backup encryption keys are kept separately from the backup archives.
  • CONSELA does not currently provide end-to-end encryption. Authorized CONSELA processing is required to index files and produce requested results.

AI and research boundaries

AI inference is configured to use provider routes that offer zero data retention where the selected route supports it. Web-research providers receive generated search queries and necessary request metadata, not the full workspace or uploaded files as a separate research payload. Their retention and processing policies differ. See the AI Disclosure and Subprocessor List before submitting sensitive information.

Backups and deletion

Encrypted infrastructure backups are stored in Cloudflare R2 with a rolling 30-day retention policy. Backup creation and restoration have been tested in a separate environment. Account, project and organization deletion workflows include grace periods and purge or quarantine processing; legal, security and accounting records may have separate retention requirements. See the Privacy Policy and Your Data Rights page for details.

Sharing and public links

Workspace access follows organization permissions. Share links are designed to be short-lived and can expose the content selected by the creator to anyone with the link. Do not place credentials, payment-card data or information you are not authorized to share in a workspace.

Incident reporting

Report suspected security or privacy issues to admin@consela.ai. Include the affected URL or feature, the approximate time, and enough detail to reproduce the issue without sending confidential content.

Scope and limitations

Our controls evolve with the product and infrastructure. CONSELA does not claim that the Service is immune to attack, that it has completed an independent penetration test or certification, or that use of the Service alone satisfies every legal or regulatory obligation. Business customers can review the Data Processing Addendum and request applicable provider information.