EX MULTIS

Security & trust

Designed for visible control.

EX MULTIS combines encrypted transport, server-side provider credentials, access controls, and traceable review records with clear guidance about what the platform can—and cannot—guarantee.

Security posture

Encrypted transport

EX MULTIS is served over HTTPS. Modern browsers should establish an encrypted connection to exmultis.com.

Server-side credentials

AI-provider credentials and privileged service keys are intended to remain on the server and are not exposed in browser code.

Access boundaries

Account authentication, project ownership checks, and database access policies restrict access to private workspaces and user content.

Traceable review

Provider reports, synthesis, and provenance records are separated so users can inspect how an answer was developed.

Institutional network access

Schools, universities, and managed networks may initially classify a recently registered domain as unknown. Network administrators should evaluate and, where appropriate, permit HTTPS access to:

  • exmultis.com and www.exmultis.com — application and public trust pages
  • *.supabase.co and *.supabase.in — authentication and application data
  • *.vercel.app and *.vercel-insights.com — hosting and operational delivery

Selected AI-provider connections are made by EX MULTIS servers, not directly from the end user’s browser. Institutions may contact us for a current network-requirements brief.

Report a vulnerability

Email support@exmultis.com with a clear description, affected URL or feature, and safe reproduction steps. Do not access other users’ data, disrupt the service, or include secrets in the initial report. We will acknowledge good-faith reports and coordinate next steps.

Responsible use and limitations

No online service can guarantee absolute security, and AI output is not guaranteed to be correct. Users and institutions remain responsible for data classification, authorized use, output review, and compliance with their own policies. Do not submit regulated or highly sensitive data unless an appropriate written agreement is in place.