The short version
A secure AI knowledge base keeps company knowledge encrypted and governed in one place, lets AI tools retrieve only the passages the requesting person may see, logs every access, and never lets the data become training material. The checklist below covers identity, data protection, AI-specific controls, and your exit plan.
Identity and access
1. Single sign-on and automatic offboarding
Connect the knowledge base to your identity provider with SAML 2.0 or OpenID Connect, and use SCIM so people who leave lose access everywhere, including their AI tools, the moment HR offboards them.
2. Required two-step verification and session limits
Enforce two-step verification by policy, and cap session lengths so a lost laptop doesn't become a permanent door.
3. Least privilege, down to the folder
Roles and groups should go down to folders: not everyone needs board notes or compensation data. The knowledge base is only as safe as its permissions.
Data protection
4. Encryption at rest and in transit, with tenant keys
Look for strong encryption at rest (such as AES-256-GCM), TLS 1.2 or newer in transit, and a separate key per customer, so your data is cryptographically isolated and can be destroyed by destroying its key.
5. Tenant isolation
Ask how tenants are separated in the database. Row-level security and a single authorization layer are good signs.
6. Encrypted backups with a defined retention
Backups should be encrypted before they leave the server and expire on a schedule you know.
AI-specific controls
7. Permission-aware retrieval
The single most important AI control: when an assistant searches, it must search as the person asking. If a person can't open a folder, their AI can't see it either. Avoid setups where one shared service account can read everything.
8. A workspace AI policy
Admins should decide whether AI tools may connect at all, which vaults or folders are searchable, and whether AI can write. Read-only is a sensible default.
9. Scoped, revocable connections
Each AI connection should carry explicit scopes (read, search, write) and a list of allowed vaults, and be revocable in one click. Standard OAuth flows through the Model Context Protocol make this visible to users.
10. No training, and know where passages go
Confirm in writing that your knowledge base vendor never trains models on your data. Then remember the AI tool itself receives the passages it retrieves, so choose an AI provider and plan whose data terms meet your requirements. A knowledge base that doesn't call any AI model itself keeps this chain short.
Oversight and exit
11. Audit logs you can export and stream
Admin changes, exports, and AI connections should be logged, exportable, and streamable to your SIEM for alerting.
12. A real exit plan
Make sure you can export everything in an open format like Markdown, and that deleting your workspace destroys its data, including its encryption key. Ask for a data processing agreement and a list of sub-processors.
How Granite covers the checklist
| Checklist item | Granite Business |
|---|---|
| 1–3 Identity and access | SAML, OIDC, SCIM, required 2FA, session limits, folder grants |
| 4–6 Data protection | AES-256-GCM with a key per vault and workspace, TLS, row-level security, encrypted 35-day backups |
| 7–10 AI controls | Permission-filtered MCP search, AI policy, scoped connections, no training, no model of its own |
| 11–12 Oversight and exit | Audit export and streaming, Markdown export, crypto-shredding, DPA |
One honest caveat: Granite encrypts on the server, not end to end, because search, the AI knowledge base, and live co-editing need it. Read the full security model.
Frequently asked questions
How do I give ChatGPT or Claude access to company documents securely?
Keep the documents in a governed knowledge base and connect the assistant through MCP with scoped, per-user access, rather than uploading files into chats. The assistant then retrieves only permitted passages, connections can be revoked, and access is audited.
What is a secure AI database?
A secure AI database stores company knowledge for AI retrieval with encryption, strong identity, permission-aware search, audit logging, and a guarantee that the data is never used to train models.
Is RAG secure?
Retrieval-augmented generation is as secure as its retrieval layer. It is safe when retrieval runs with the requesting user's permissions, the index is encrypted and tenant-isolated, and the AI provider's data terms are acceptable.