Permission-aware RAG appliance
Clearance
Syncs S3, Confluence, and Google Drive together with each document's access list. At query time, retrieval is filtered to what the asking user can already see, before any text reaches the model.
- Source permissions preserved on every sync
- Filtering happens at retrieval, not in the prompt
- Runs as containers in your VPC
indexed chunk metadata · example
source: confluence://SRE/payments-runbook acl: [group:sre-payments, user:cto@example.com] synced: 2026-09-30T14:02Z
Read how it works