Secure knowledge base · Private AI database
The secure knowledge base for companies that can't leak.
Granite keeps company knowledge encrypted with a key per workspace, behind single sign-on, with every access on the record. Your AI tools get a governed way in, and your data never becomes anyone's training set.
In short
A secure knowledge base protects company knowledge with encryption, strong identity, least-privilege access, and auditing, and lets you take it back out. Granite encrypts every vault with AES-256-GCM under a per-workspace key, enforces SSO and two-step verification, isolates tenants with row-level security, logs every admin and AI access, and destroys a workspace's key when it's deleted. It's also a secure AI database: AI tools search it only within the permissions you set.
Six layers of protection
Security that's structural, not a setting.
A key for every vault
Files are encrypted with AES-256-GCM before they're written. Each vault's key is wrapped by your workspace key, itself wrapped by a master key that never enters the database or any backup.
SSO, SCIM, and 2FA
SAML 2.0 and OpenID Connect single sign-on, automatic provisioning and removal with SCIM, required two-step verification, and session limits.
Least privilege
Owner, admin, member, and guest roles, groups, and folder-level grants for readers, commenters, and editors.
Tenant separation
Every request passes one authorization layer, and row-level security keeps tenants apart in the database.
On the record
Admin actions, exports, and AI tool access in an audit log you can export or stream.
Crypto-shredding when you leave
Delete a vault and its files and key go with it. Delete a workspace and, once it is purged 30 days later, its key is destroyed, so nothing it held can be decrypted again; encrypted backups age out after 35 days.
Private AI, without a private model.
Granite doesn't run or call an AI model. You connect the AI tool your company approved; Granite hands it only allowed passages, only when asked.
Never training data. Never sold.
Your notes are never used to train AI models, never sold, and never shown to advertisers. This website doesn't use cookies or trackers either.
Plain files, any day.
Export any vault as Markdown, or your entire account. A knowledge base you can't leave isn't secure, it's a hostage.
Clear about the trade-off.
Encryption is server-side, not end to end, so search, the AI knowledge base, and live co-editing can work. We document exactly what the server can read and why.
Security checklist
What your security review will ask.
| Requirement | Granite Business |
|---|---|
| Encryption at rest | AES-256-GCM, a key per vault, wrapped per workspace |
| Encryption in transit | TLS 1.2 or newer, HSTS |
| Single sign-on | SAML 2.0 and OpenID Connect |
| User provisioning | SCIM, domain capture, invitations |
| Multi-factor authentication | Authenticator apps, can be required by policy |
| Role-based access control | Roles, groups, folder-level grants |
| Audit logging | Export (CSV, JSON) and streaming |
| Data export and deletion | Full export; deletion destroys keys |
| Backups | Encrypted before upload, 35-day retention |
| AI governance | Per-workspace AI policy, scopes, folder selection, audit |
| AI training on customer data | Never |
| Data processing agreement | Yes, with a public sub-processor list |
What makes a knowledge base secure for companies?
A secure company knowledge base encrypts data at rest and in transit, ties access to your identity provider with SSO and SCIM, enforces least-privilege permissions, logs every sensitive action, and lets you export and permanently delete your data. Granite does all of these and adds governed access for AI tools.
Is Granite end-to-end encrypted?
No. Granite encrypts your data at rest on the server with a key per vault and per workspace, and in transit with TLS. It is not end to end, because full-text search, the AI knowledge base, and live co-editing need the server to read notes. Your notes are never used to train AI models, and Granite has no AI model of its own.
Is Granite a secure AI database for companies?
Yes. Granite works as a secure AI database for company knowledge: content is encrypted, every AI request is authenticated and filtered by the requester's permissions, admins decide which vaults and folders AI may use and whether it may write, and every connection is audited.
Can admins stop AI tools from reading certain folders?
Yes. Workspace admins choose which vaults and folders are in the knowledge base, can restrict AI tools to read-only, can turn AI access off entirely, and see AI connections in the audit log. Users can only grant an AI tool access to what they can already open.
Is Granite GDPR-ready?
Granite offers a data processing agreement, a public list of sub-processors with 30 days' notice of changes, full data export, account and workspace deletion with crypto-shredding, and a documented process for data subject requests. The site itself uses no cookies or trackers.
What happens to our data if we cancel?
Nothing is deleted when you downgrade; syncing new files pauses if you're over a limit, and you can always read and export everything. If you delete your workspace, it is purged after 30 days and its key is destroyed, so its data can't be decrypted again; encrypted backups age out within 35 days.
Give your company a memory it can trust
Free for one person. Business is free for 14 days, no card required.
- Encrypted with a key per vault
- Never used to train AI
- Export as Markdown anytime