Security model

Where data lives. What crosses the wire. What never does.

Principles

Data classification

DataWhere it livesEncryptedSent over wire?
Your .xlsx workbookWherever you put itPer your OS settingsNever
Sheet context (per turn)RAM onlyTLS to AI providerYes — to AI only
Chat history%APPDATA%\HISAB\chats\NTFS permissionsNo
Audit log%APPDATA%\HISAB\audit.dbNTFS permissionsNo
ERP credentials%APPDATA%\HISAB\credentials.datDPAPI (per-user)To ERP API only, over TLS
Skill code (yours)%APPDATA%\HISAB\skills\NTFS permissionsNo
MCP bearer token%APPDATA%\HISAB\mcp-token.txtDPAPI (per-user)Localhost only

Operating modes

Set in Settings → Operating mode:

Compliance roadmap

Security disclosures: email security@hisab360.com. PGP key on our security page.