Security & governance
Enterprise-grade controls, on by default.
ChatLite is built so organizations can adopt AI without giving up oversight. Access, identity, content, and data are all governed, and your content is never used to train third-party models unless you opt in.
Single sign-on (SSO)
OAuth-based SSO via NextAuth lets organizations centralise access through their existing identity provider.
Multi-factor authentication
TOTP-based MFA with one-time backup codes protects every account against credential theft.
Device & session control
Track active sessions per device and remotely sign out of all devices in a single action.
Guardrails on every turn
Input and output are screened for prompt injection, jailbreaks, and policy violations before a response is shown.
PII detection & redaction
Personally identifiable information, secrets, and credentials are detected and redacted, with a full audit trail of each decision.
Encryption & key management
Sensitive fields (MFA secrets, API keys, OAuth tokens) are encrypted at rest, with secrets held in Azure Key Vault.
Role-based access control
Granular roles and permissions, owner transfer, and per-organization model access keep usage governed.
Your data is not used to train models
Customer content is processed only to deliver the service and is never used to train third-party foundation models unless you explicitly opt in.
Data handling
Where your data goes, and where it doesn't.
Clear boundaries on how prompts, files, and account data are processed, stored, and retired.
Routed to your chosen model
Prompts are forwarded only to the model provider you select to answer your request.
Never used for training
Customer content is not used to train third-party foundation models unless you explicitly opt in.
Encrypted in transit & at rest
Traffic is protected with TLS and sensitive fields are encrypted at rest.
Deleted within 30 days
Deleted accounts are removed or anonymised within 30 days, subject to legal retention.
Secrets in Azure Key Vault
API keys and secrets are held in Azure Key Vault, never in application code.
Access restricted & logged
Access to production systems is limited to authorised staff and logged for accountability.
Full detail lives in our Privacy Policy and Terms of Service.
FAQ
Security FAQ
Is ChatLite secure for business and enterprise use?
Yes. ChatLite provides SSO, multi-factor authentication, device and session control, encryption at rest, role-based access control, and guardrails that screen every prompt and response for PII, secrets, and prompt injection.
Does ChatLite support SSO and MFA?
Yes. Organizations can sign in through OAuth-based single sign-on, and every account can enable TOTP-based multi-factor authentication with backup codes.
Does ChatLite use my data to train AI models?
No. Your prompts, files, and outputs are processed only to provide the service and are never used to train third-party foundation models unless you explicitly opt in.