Security & trust · operational assurance

Visible control.
Institutional readiness.

EX MULTIS brings encrypted transport, server-side credentials, access boundaries, and traceable review records into one clear security posture for research teams, academic institutions, and industry organizations.

A security record that is legible to the people doing the work and the people accountable for approving it.

Security posture

Controls that hold the record together.

A shared foundation for individual teams, industry organizations, and institutions that need a clear basis for access and review.

01

Encrypted transport

EX MULTIS is served over HTTPS. Modern browsers should establish an encrypted connection to exmultis.com.

02

Server-side credentials

AI-provider credentials and privileged service keys are intended to remain on the server and are not exposed in browser code.

03

Access boundaries

Account authentication, project ownership checks, and database access policies restrict access to private workspaces and user content.

04

Traceable review

Provider reports, synthesis, and provenance records are separated so users can inspect how an answer was developed.

Data boundary

Each request has
a visible destination.

Only the material needed for a selected route is sent. The record distinguishes the EX MULTIS workspace, the selected AI provider, and the review record a user can inspect.

01 · EX MULTIS workspace

Project context and review record

Account access, project ownership checks, and the review history remain within the application boundary.

02 · Selected provider route

Only the requested material

Content needed to answer the request is sent to the provider selected for that route, under the data practices described for that provider.

03 · Responsible reviewer

Human judgment remains required

The record exposes support, disagreement, and uncertainty; it does not transfer responsibility for using the result.

Institutional network access

Review the perimeter
before access begins.

Schools, universities, and managed networks may initially classify a recently registered domain as unknown. Network administrators should evaluate and, where appropriate, permit HTTPS access to these service boundaries.

Network review recordApproved destinations
Application and public trust pagesexmultis.com · www.exmultis.com
Authentication and application data*.supabase.co · *.supabase.in
Hosting and operational delivery*.vercel.app · *.vercel-insights.com
Selected AI-provider connections are made by EX MULTIS servers, not directly from the user’s browser.

Report a vulnerability

Good-faith reporting
has a clear path.

Email support@exmultis.com with a clear description, affected URL or feature, and safe reproduction steps. Do not access other users’ data, disrupt the service, or include secrets in the initial report.

We will acknowledge good-faith reports and coordinate next steps.

Responsibility remains shared

Support for secure work.
Not a guarantee of it.

No online service can guarantee absolute security, and AI output is not guaranteed to be correct. Users and institutions remain responsible for data classification, authorized use, output review, and compliance with their own policies.

Do not submit regulated or highly sensitive data unless an appropriate written agreement is in place. For security, privacy, accessibility, procurement, or institutional-review questions, contact support@exmultis.com.

Review the Trust Center →