Security · Controlled beta

Trust starts with an honest retrieval boundary.

Find Anything shows what the authorized workspace searched and what it could not access. It never claims awareness of undiscovered systems.

Application access

Current

ChatGPT identity plus a server-side invite or admin check protects every product route.

Google Drive scope

Current

The connector requests Google Drive read-only access. OAuth state and PKCE protect authorization initiation.

Credentials

Current

Access and refresh tokens are encrypted before D1 storage and are not exposed to browser responses.

Workspace isolation

Current

Workspace membership and permission-scoped file IDs are checked server-side for retrieval and connector operations.

Disconnect and deletion

Current

Disconnect revokes where possible and deletes connector credentials, indexed files, and dependent workspace retrieval data.

Analytics

Current

Coarse first-party events exclude file contents, tokens, filenames, excerpts, and raw search queries.

Additional connectors

Planned

Notion, Microsoft 365, Slack, GitHub, Jira, Dropbox, and Box are not currently live.

Certifications

Not claimed

Find Anything does not claim SOC 2, HIPAA, ISO 27001, or other security certification.

Report a security concern

Email security@findanything.dev. Do not include active credentials or private document contents in the initial report.