← Articles

Trusted with the data you can't afford to leak

A company that handles people's most sensitive records put ManuFind through a security review — isolation, who-can-see-what, and the cost of the AI. Here's why it earned the top pick.

Dana's company handles the kind of information you don't get a second chance with — personal records, health and identity data, the things that are strictly need-to-know. So when ManuFind's name landed in the bucket of tools the company was considering, it didn't get a free pass. It got a security review. Three questions, in plain terms: Is our data actually separated from everyone else's? Can we control exactly who sees what? And is the AI something we can afford and trust — or a black box with a surprise bill?

Here's what she found.

Your data stays yours

The first thing Dana wanted to rule out was the nightmare scenario: one customer's data bleeding into another's because everyone shares the same plumbing. With ManuFind, they don't. Each customer runs on its own database, its own application service, its own cache, and its own document storage — encrypted, with its own key. It isn't one big shared pool where a single bug spills one company into the next; the separation is built into the infrastructure itself.

On top of that separation, every request inside the platform carries a tenant identity that fails closed. Ask for anything outside your own organization and the system doesn't error out or leak a hint — it simply returns nothing, by design. That's the safe default: when in doubt, show nothing.

And it holds even when you connect from the outside. If a developer wires ManuFind into another system with an API key, or an AI assistant connects through our MCP tools, that connection inherits the exact permissions of the person behind it — re-checked on every single request, not just when the key was created. A token can never do more than its owner can, and it can never reach another organization's data. Downgrade someone's access and their existing keys downgrade with them, immediately.

Need-to-know, actually enforced

Separation between companies is table stakes. The harder problem for Dana was separation inside her own company — making sure the right people see the right things and no one else.

ManuFind uses four everyday roles. A viewer can read. A user can read and add or edit documents. A manager can do all that, plus delete and decide who has access to which folders. An admin runs the workspace. Most people only ever need one of these, and the boundaries are enforced on the server, not just hidden in the interface.

Then there's the control that mattered most for regulated data: folder-level access. Put a document in a restricted folder, and anyone without a grant doesn't just lose the download button — the document becomes invisible. Not in their browse view. Not in their search results. Not in answers from ManuFinder AI. It's as if, for them, the document doesn't exist.

That last part is the one people test the hardest, so it's worth being clear about. Someone could try to coax the assistant into leaking — "what was our revenue last year?" — hoping the AI will quietly read a document they were never cleared to open. It won't. ManuFinder AI answers only from the same access-filtered library the asker can already see, so a restricted document is never even retrieved, let alone quoted. On top of that, the assistant has guardrails that refuse the manipulation outright. You can't prompt your way around your own permissions.

Honest limits, real costs

Dana's third question was the one vendors usually get cagey about: what does the AI actually cost, and where are the limits?

ManuFind tracks cost and AI usage from the very first query — every AI request is logged with its real, measured cost, so usage is something you can see rather than guess at. Plan limits aren't numbers someone made up to look generous; they're set from measured usage and backed by unit tests, so what the plan promises is what the system actually enforces. No mystery throttling, no surprise overage.

There's a quieter benefit, too. Your documents aren't poured into some shared, outside assistant that learns from everyone's data at once. They stay inside your own isolated workspace, answered only under your own access rules. The intelligence comes to your data — your data doesn't go wandering off to it.

Built to the standard, every release

Underneath all of it, ManuFind is designed to follow SOC 2 and HITRUST security guidelines. Documents are encrypted at rest (AES-256) and in transit (TLS). Every meaningful action — and every AI query — is written to an append-only audit log that can't be quietly edited after the fact. The platform is monitored continuously. And security tooling isn't a one-time audit that gets stale; it's part of the build-and-test cycle on every release, so the protections keep pace with the threats.

Connects to what your team already uses

None of this matters if people won't use it. So ManuFind meets teams where they are: it imports automatically from Google Drive, OneDrive, Confluence and your computer's local folders, and day to day it works the way people already expect — drag a document in, ask a question, get an answer. Adoption doesn't mean tearing anyone off the tools they know; it means finally being able to find and trust what's in them.

Why it earned the top pick

By the end of the review, Dana could answer the only question that really mattered: could she put the company's most sensitive data here and defend that decision? Isolation she could point to. Access controls she could prove. AI costs she could see. Standards built into every release. Not a leap of faith — a defensible choice.

If your organization is trusted with data that can't afford to leak, we'd welcome the same scrutiny. Talk to us about a security review.