LoreGraph product docs

Security, Privacy, and Data

Summary

LoreGraph is designed around controlled workspace access, review before publishing, and careful handling of uploaded business documents.


Who this is for

  • Workspace admins
  • Security reviewers
  • Legal reviewers
  • IT administrators

Before you start

  • Know which workspace owns the data.
  • Review the source documents for sensitivity before upload.
  • Use the legal security page and subprocessors page for formal review details.

Concepts

Uploaded documents are private to the workspace.

Learners do not automatically see source documents.

Courses are not public unless published that way.

AI helps generate drafts from uploaded materials. Admins review content before publishing.

Do not claim customer data is never used for training unless that is contractually true for the specific AI provider setup.

Access control depends on admin, creator, learner, and workspace boundaries.

Steps

  1. Upload documents only into the correct workspace.
  2. Keep courses in draft until review is complete.
  3. Choose private or invite-only access for internal training.
  4. Review AI-generated content before publishing.
  5. Delete source documents, courses, learners, or workspaces according to the product controls available.
  6. Review subprocessors and compliance status before enterprise rollout.

Settings reference

SettingWhat it doesRecommended default
Workspace privacyKeeps uploaded materials scoped to the workspace.Use one workspace per business in the MVP.
Learner accessControls what learners can see.Learners should see assigned courses, not raw source files by default.
Publishing modeControls public or private course access.Use private for internal documents.
DeletionRemoves documents, courses, learners, or workspace data where supported.Confirm downstream effects before deletion.

Example

A company uploads an internal security policy, keeps the generated course in draft, reviews the AI output, publishes it privately, and assigns it only to employees who need the training.

Common mistakes

  • Uploading sensitive content into a personal or wrong workspace.
  • Publishing internal training publicly.
  • Making unsupported claims about AI provider data training.
  • Deleting source files without understanding whether generated courses remain available.

Compliance roadmap

ItemStatus guidance
SOC 2Do not describe LoreGraph as SOC 2 certified unless a current certification is in place. Treat as planned or under review until confirmed.
HIPAADo not use LoreGraph for HIPAA-regulated workflows unless a supported agreement and product configuration explicitly allow it.
DPAUse the contract or sales process to confirm whether a DPA is available for the customer.
Enterprise security reviewAvailable only when included in the enterprise sales or procurement process.

Last updated: May 30, 2026