Trust & Security

Tenant isolation is the default, not an add-on.

SeleneX connects multiple companies' engineering data in one workspace. That only works if every organization can trust exactly what is, and isn't, visible to anyone else.

Pre-pilot checklist

Tenant isolation and IDOR tests
Permission matrix tests
Encrypted secrets
Encrypted storage
AI subprocessor disclosure
Per-document AI opt-out
Audit events
Backup and restore tested
Malware scanning
File size and type limits
Rate limiting
Secure invitation tokens
Deletion and retention workflow

Tenant isolation

Default-deny is not a policy, it's the code path

Every endpoint checks an explicit grant before returning data. An organization with no standing on a resource gets a not-found response, never a hint that the resource exists.

Evidence custody

Link SharePoint evidence, don't duplicate it

SeleneX links to a customer's own SharePoint library and keeps a synced reference with a tracked freshness state, reading only what the organization's own permissions already allow.

Human-approved AI

Every AI output is a draft until approved

AI-assisted extraction and document drafting never writes directly into the shared record. A named engineer reviews and approves before a proposal counts as data.

Auditability

Every decision is attributable

Requirement changes, parameter revisions, submissions, review decisions, and change requests are recorded against who made them and when.

Reliance boundary

Trust starts with saying what the product does not do.

SeleneX is engineering-collaboration infrastructure: it moves requirements, parameters, and deliverables between organizations.

SeleneX does not claim SOC 2, ISO 27001, or other third-party certification until independently audited and certified.

Data submitted to AI-assisted features is never used to train models shared across customers.

For a pilot, we ask customers to use unclassified, anonymized data agreed with the customer in advance.

Governance documents

Standard agreements before the first pilot.

Data Processing Agreement

Request →

Privacy Policy

Request →

Terms of Service

Request →

Acceptable Use Policy

Request →

Incident Response process

Request →