Granite

Secure knowledge base · Private AI database

The secure knowledge base for companies that can't leak.

Granite keeps company knowledge encrypted with a key per workspace, behind single sign-on, with every access on the record. Your AI tools get a governed way in, and your data never becomes anyone's training set.

In short

A secure knowledge base protects company knowledge with encryption, strong identity, least-privilege access, and auditing, and lets you take it back out. Granite encrypts every vault with AES-256-GCM under a per-workspace key, enforces SSO and two-step verification, isolates tenants with row-level security, logs every admin and AI access, and destroys a workspace's key when it's deleted. It's also a secure AI database: AI tools search it only within the permissions you set.

Six layers of protection

Security that's structural, not a setting.

01 · Encryption

A key for every vault

Files are encrypted with AES-256-GCM before they're written. Each vault's key is wrapped by your workspace key, itself wrapped by a master key that never enters the database or any backup.

02 · Identity

SSO, SCIM, and 2FA

SAML 2.0 and OpenID Connect single sign-on, automatic provisioning and removal with SCIM, required two-step verification, and session limits.

03 · Access

Least privilege

Owner, admin, member, and guest roles, groups, and folder-level grants for readers, commenters, and editors.

04 · Isolation

Tenant separation

Every request passes one authorization layer, and row-level security keeps tenants apart in the database.

05 · Audit

On the record

Admin actions, exports, and AI tool access in an audit log you can export or stream.

06 · Deletion

Crypto-shredding when you leave

Delete a vault and its files and key go with it. Delete a workspace and, once it is purged 30 days later, its key is destroyed, so nothing it held can be decrypted again; encrypted backups age out after 35 days.

AI

Private AI, without a private model.

Granite doesn't run or call an AI model. You connect the AI tool your company approved; Granite hands it only allowed passages, only when asked.

Data

Never training data. Never sold.

Your notes are never used to train AI models, never sold, and never shown to advertisers. This website doesn't use cookies or trackers either.

Exit

Plain files, any day.

Export any vault as Markdown, or your entire account. A knowledge base you can't leave isn't secure, it's a hostage.

Honesty

Clear about the trade-off.

Encryption is server-side, not end to end, so search, the AI knowledge base, and live co-editing can work. We document exactly what the server can read and why.

Security checklist

What your security review will ask.

RequirementGranite Business
Encryption at restAES-256-GCM, a key per vault, wrapped per workspace
Encryption in transitTLS 1.2 or newer, HSTS
Single sign-onSAML 2.0 and OpenID Connect
User provisioningSCIM, domain capture, invitations
Multi-factor authenticationAuthenticator apps, can be required by policy
Role-based access controlRoles, groups, folder-level grants
Audit loggingExport (CSV, JSON) and streaming
Data export and deletionFull export; deletion destroys keys
BackupsEncrypted before upload, 35-day retention
AI governancePer-workspace AI policy, scopes, folder selection, audit
AI training on customer dataNever
Data processing agreementYes, with a public sub-processor list

FAQ

Security questions.

Report a vulnerability to security@granite.md.

What makes a knowledge base secure for companies?

A secure company knowledge base encrypts data at rest and in transit, ties access to your identity provider with SSO and SCIM, enforces least-privilege permissions, logs every sensitive action, and lets you export and permanently delete your data. Granite does all of these and adds governed access for AI tools.

Is Granite end-to-end encrypted?

No. Granite encrypts your data at rest on the server with a key per vault and per workspace, and in transit with TLS. It is not end to end, because full-text search, the AI knowledge base, and live co-editing need the server to read notes. Your notes are never used to train AI models, and Granite has no AI model of its own.

Is Granite a secure AI database for companies?

Yes. Granite works as a secure AI database for company knowledge: content is encrypted, every AI request is authenticated and filtered by the requester's permissions, admins decide which vaults and folders AI may use and whether it may write, and every connection is audited.

Can admins stop AI tools from reading certain folders?

Yes. Workspace admins choose which vaults and folders are in the knowledge base, can restrict AI tools to read-only, can turn AI access off entirely, and see AI connections in the audit log. Users can only grant an AI tool access to what they can already open.

Is Granite GDPR-ready?

Granite offers a data processing agreement, a public list of sub-processors with 30 days' notice of changes, full data export, account and workspace deletion with crypto-shredding, and a documented process for data subject requests. The site itself uses no cookies or trackers.

What happens to our data if we cancel?

Nothing is deleted when you downgrade; syncing new files pauses if you're over a limit, and you can always read and export everything. If you delete your workspace, it is purged after 30 days and its key is destroyed, so its data can't be decrypted again; encrypted backups age out within 35 days.

Give your company a memory it can trust

Free for one person. Business is free for 14 days, no card required.

  • Encrypted with a key per vault
  • Never used to train AI
  • Export as Markdown anytime