Authentication
Magic links, passkeys, recovery codes and HttpOnly same-origin sessions.
Private by default
WorldIR separates organization data in PostgreSQL row-level security and physical object and graph scopes. Agents cannot silently create a second write path.
Magic links, passkeys, recovery codes and HttpOnly same-origin sessions.
Role checks in handlers plus tenant-scoped database transactions.
Graph writes only through validated proposals; cited answers reject unsupported citations.
No training on private files. Export and erasure are organization-controlled and audited.