Security and privacy model
The controls that separate accounts, sources and generated output.


Authenticated ownership
Protected document, conversation, note and annotation operations require an authenticated session. Backend ownership checks are the enforcement point; hiding a control in the browser is never treated as authorization.
Tenant isolation
Retrieval and persistence are scoped to the current owner and selected resources. Citely checks parent relationships when a conversation, annotation or note refers to another record.
Generation guardrails
Document passages remain untrusted input. Output checks target protected instructions, credentials and unsupported claims while allowing ordinary technical names and supported negative facts.
Product status
Citely is in beta. Security and privacy claims on this documentation describe implemented application boundaries, not a certification. The privacy page remains accessible but is excluded from search indexing until policy approval is established.