Your data stays under your control.
Pindot is built for organisations that cannot compromise on where their data goes. Run it on your own servers, fully air-gapped, or hosted by us. Wherever it runs, it only reads your systems, never changes them, and can show where every answer came from.
Nothing leaves without your say-so.
Pindot reads from your systems and answers your team. Findings go out to tools like Jira or Slack only when an administrator switches that on, and nothing phones home.
On-premise. Everything runs inside your network. The only way out is a destination you switch on. Nothing is sent outside.
- Your systemsYour network
- PindotYour network
- Your teamYour network
- Jira and Slack stay off until you switch them on.
On-premise. Everything runs inside your network. The only way out is a destination you switch on.
Three lines of defence.
- 1
Your credentials stay locked away
The passwords and keys Pindot uses to read your systems are encrypted the moment they are saved and never shown again: not to your users, not to us, and never to the AI.
Encrypted credentials
- 2
Read-only, by design
Pindot observes. It connects with read-only access, so it cannot change your production systems, even by mistake. Your own systems refuse the attempt, not just our software.
Read-only access
- 3
Every answer is on the record
Each question leaves an audit record of where Pindot looked, what it found and what it answered. Pindot only ever adds to that record. It never edits or removes it.
Full audit trail
How we handle your data.
You choose where it runs
On your own servers, fully air-gapped if you need it, or hosted by us. The product and its protections are the same either way.
Sensitive fields masked
Fields you mark as personal data are masked in every result, before an answer is written from it.
Access by team and person
You decide which sources each team or person can ask about, down to a single table. The AI is only shown what the person asking may see.
Questions kept private
The audit trail keeps a fingerprint of each question rather than its words, and chat history can be switched off entirely.
No lock-in
Built on open, widely used technology. There is no proprietary runtime to license, and nothing to rip out if you move on.
Honest when data is missing
When a source cannot be reached, the answer says so and names it. A partial answer never passes for a complete one.
Built for the most regulated environments.
From the first design decision, Pindot is shaped around what regulators, auditors and security teams ask for.
- On-premise
- Fully air-gapped
- Read-only access
- Encrypted credentials
- Full audit trail
- Role-based access
Security FAQ
Anything else your security team needs to know, bring it to the demo.
Stop digging through logs at 2am.
Bring your own 02:14, a real incident from your systems. We will show you how Pindot finds the cause, and where every piece of evidence came from.