Back to access
Security

Data & Privacy

Last updated: April 24, 2026

1. Ownership and scope

Memory in Layar is scoped to the signed-in user and their Vault. Documents, exports, Ask retrieval, and connected app access are intended to resolve against that ownership boundary before content is returned.

2. Storage and transport

Layar serves traffic over HTTPS in production. File uploads use signed upload URLs, and stored files are fetched with signed read URLs rather than public object paths.

3. Secrets and exports

Connected provider keys are stored encrypted server-side. Exports are generated on demand and checked against the owner before they are returned.

4. Beta limits

Layar is still in beta. Operator access may still exist for service operation, debugging, and support, and enterprise controls are not yet part of the product promise unless they are explicitly shipped and documented.