Know exactly what your AI read.
Exagram only sees what a Connection asks it for. Every one of those requests is recorded, redacted where you choose, and limited to the folders you set.
Every read, with the Revision it read.
The Ledger records which Connection read which Revision, whether it got the original or Redacted Text, and what was withheld. Owners see their files’ rows; Admins see the whole Workspace in Audit.
Personal details stay out of the AI.
With redaction on, a Connection reads Redacted Text: emails, phone numbers and ID numbers are replaced. Set it on a file, a project or the Workspace; the nearest setting wins. People reading through a share or a Link get the original.
Controls you can check.
What runs before anything leaves, as it appears on the Security page of the app.
Folder access per Connection
Cut off a Connection at once
Publish policy per project
Google sign-in, SSO on Business
Encrypted at rest
Run it on your own VM
Before your security review.
No. Exagram only sees what a Connection asks it for: the Artifacts it reads and the Revisions it writes. Pasted text and uploads to the AI tool never pass through Exagram.
Revoke the Connection, the Links and the Grants. Tokens the Connection already holds stop working. Information already returned to an AI tool cannot be removed.
Owners see the rows for their own files. Workspace Admins see every row in Audit.
Yes. Self-host Exagram on one Linux VM with Docker Compose. Business on Exagram Cloud can choose a data region.