Built to clear security review.
Ceggesta sits in the path of what your people ask AI. We treat that as the most sensitive data a company produces — here is exactly how.
Redaction before storage
Personal data is scrubbed from prompt content before anything is written. Redaction is not a setting a request can skip — it runs ahead of storage, every time. Raw prompts are never persisted.
A 30-day clock
Stored prompt context carries its own expiry: it self-erases in 30 days. The surrounding event records — tokens, cost, attribution, tags — expire at 90. Nothing about the content lingers because a record does.
Your org, your switch
Prompt storage has a per-organization opt-out. Turn it off and Ceggesta keeps attributing usage and cost, without retaining prompt content for your organization.
Closed-set attribution
When Ceggesta infers who was behind a request, it chooses from your own roster — a closed set. It cannot invent a user, and an explicit attribution from your side always wins over an inferred one.
Grounded numbers
Every figure in a briefing is re-verified against the underlying query before it renders. If a number can’t be traced back to the data, it doesn’t ship.
Self-hosted option
For teams that can’t send analysis anywhere, in-cluster inference keeps model calls inside your boundary.
Your keys, your models
Ceggesta forwards requests to your existing providers — Anthropic, OpenAI, Google — under your own accounts. We never intermediate your model choice.
Access is role-gated
Inside your organization, prompt-content access is a distinct, grantable capability — not a default. Seeing usage and cost does not mean seeing content.
Questions we hear first
Do you train models on our data?
No.
Can Ceggesta staff read our prompts?
Redaction runs before storage, and access is role-gated. Raw prompt content is transit-only.
Can we turn prompt storage off entirely?
Yes — per organization, effective immediately for new traffic.
Questions we didn’t answer
sales@ceggesta.com — we reply to every message.