Last updated: August 20, 2026
Theama is a multi-tenant platform, which means many businesses use it at once. Keeping each customer's financial, sales, and customer data strictly inside their own environment is a first-class design goal — not an afterthought. This page explains, in plain language, exactly how we protect your data, especially when you use the AI advisor.
Our guiding principle: we never rely on the AI to police its own boundaries. Isolation is enforced by the architecture around it — signed identities, per-tenant data scoping, and strict data minimisation — so your data stays yours.
Access is controlled by a cryptographically signed security token issued when you log in and verified on our servers for every single request. Your data boundary is derived from that verified token — it can never be spoofed or overridden by anything sent from a browser or app. Sessions use hardened, HTTP-only cookies over encrypted (TLS) connections and can be revoked across all your devices instantly.
Every dashboard metric, integration credential, and AI conversation is stored and retrieved scoped strictly to your account and team. One customer's request can never reach another customer's data. We connect to your tools (CRM, finance, security, and more) using the credentials you connect — we do not pool different customers' data into any shared store or search index.
When you ask the AI advisor a question, it receives only high-level summary figures (for example, "YTD revenue" or "security score") plus the question you typed. These figures are assembled on our servers from your account only — never taken from anything the browser or app sends — so they cannot be swapped for another customer's data.
It never receives raw customer lists, individual invoices, contact details, or account numbers.
The AI has no access to our database and no ability to run queries or tools. It can only reason over the small summary handed to it — so it is architecturally incapable of "dumping" data or reaching another customer's information.
Every question is screened. Attempts to extract system instructions, raw records, or another customer's data are blocked before they ever reach the model.
Every response is redacted. An automatic filter strips emails, card and account numbers, and similar identifiers from AI replies, while leaving ordinary business figures intact.
Every AI request is logged. Owners can review a full, timestamped record of AI activity for their team from inside the app.
For security or data-protection questions, contact admin@cloudknots.com. See also our Privacy Policy.