Security & Trust
Last updated: July 22, 2026
OCTA8 is designed for enterprise environments where database access, permissions, credentials, and auditability matter. This page summarizes how the platform approaches security for AI-powered analytics over ERP systems, SQL databases, spreadsheets, and documents.
Security principles
- Authenticated access with role-based permissions and project-level governance
- Encrypted database credentials, resolved only when needed by authorized backend services
- Controlled, read-focused SQL execution for analytics workflows
- API protection with authentication, rate limiting, and internal service signatures
- Signed URL patterns for sensitive documents and reports
- Operational visibility through activity logs, query logs, streaming jobs, and queues
Access control
Administrators can manage users, roles, permissions, sessions, and project-level access so business teams get answers without opening uncontrolled database access. Sensitive actions stay behind authenticated APIs and policy checks.
Credential protection
Connector credentials are encrypted at rest and resolved only when authorized backend services need them to run analytics jobs. Marketing demos and scoping conversations are designed around controlled, read-focused access — production write access is not required for demo evaluation.
Safer query execution
OCTA8 grounds AI workflows in the project schema, SQL validation, query execution, and retrieved document context. That design helps keep answers tied to real data and reduces the risk of uncontrolled generative output.
API and file protection
Sensitive APIs are protected with authentication, rate limiting, and internal service signatures. Documents and reports can use signed access patterns to reduce public exposure of internal files.
Monitoring and auditability
Streaming jobs, queues, activity logs, and query logs support operational visibility for IT and data teams reviewing how the platform is used across projects.
Compliance posture
OCTA8 is designed for GDPR-conscious, security-sensitive enterprise deployments. Deployment model, data residency, subprocessors, and certification details are reviewed during technical and procurement scoping.
Request a security review
Book a technical demo and select “Security review” as your main goal, or contact security@octa8.ai for a deeper architecture discussion.