Security
Security information for Curiosity Workspace: the advisories we publish, how to report a vulnerability, and where each of the product's security controls is documented.
Curiosity Workspace is deployed to infrastructure you operate. The controls below are the ones the product gives you; how they are configured for a given deployment is up to you.
Report a Security Issue
Found a vulnerability? Email security@curiosity.ai. We acknowledge reports within two business days.
Where the controls are documented
| Area | What it covers | Documentation |
|---|---|---|
| Authentication | Local accounts, TOTP second factor, SSO through OIDC and SAML 2.0 | Single Sign-On |
| Authorization | Access groups over node types, fields, endpoints, AI tools, and assistants | Permission model · Access control model |
| API tokens | Workspace, endpoint, and connector token scopes | Token scopes |
| Encryption | Optional AES-256 encryption of graph content at rest, TLS and HSTS in transit | Security baseline · Configuration reference |
| Users and groups | Provisioning, group membership, administration | User management |
| Audit and monitoring | Workspace logs, audit trail, uptime, live activity | Monitoring |
| AI data handling | What reaches a model provider, and how to restrict it | LLM configuration |
| Patching | Upgrading a deployment to a build carrying a fix | Upgrades and migrations |
Contact
- Security vulnerabilities — security@curiosity.ai
- Privacy and data processing enquiries — privacy@curiosity.ai
- Everything else — hello@curiosity.ai
Compliance documentation, certification artefacts, and security questionnaires are handled outside this site — request them through your account manager or hello@curiosity.ai.