Ask the other vendors this question.
When you next take a demo from any AI knowledge platform, ask where your private context goes and who can read it. Most of them will tell you about their certifications. Ask again about the architecture.
One for the company, scoped to what you are allowed to see. One that is yours, encrypted with your own key, that nobody else can read. Your agents sit in the middle and can use both.
Ask someone to connect their email, their LinkedIn and their WhatsApp to a shared company brain and they will say no, and they will be right to. Most of the value in a knowledge system comes from exactly that data: who knows whom, what was promised on a call, which relationship is actually warm. It is also the data people least want their employer reading.
Most platforms resolve this by not asking. They index the document stores, skip the personal context, and produce a system that knows what your company wrote down but nothing about how it works. We resolved it differently.
The Two Brains
Ask an agent to work out who to follow up with and why, and the reason comes from company context while the relationship comes from your own. The task completes without your personal data ever reaching the company brain.
Everything the firm knows, scoped by role.
Shared. A team lead sees their team's work. Finance and HR see payroll. Nobody sees a restricted deal they are not on.
Your agents read from both, for one task, without moving anything between them.
No path runs from the personal brain into the company brain.
Yours alone, encrypted with your own key.
Private. Your email, your LinkedIn, your WhatsApp, whatever you like. The CEO cannot read it. We cannot read it.
How the Permissions Work
Most systems apply permissions at the document or folder level. That breaks the moment a system starts deriving facts, because the derived fact has no folder.
We tag permissions on every object in the graph. Every node, whether it is a primary entity, a data chunk or a source file. Every edge, because relationships carry information of their own, and knowing that two companies are connected is sometimes more sensitive than either record.
The result is that access changes the shape of what you see, not just the volume. A user without clearance does not see a redacted version of the graph. They see a graph in which that part does not exist.
Payroll is visible to finance and HR. A restricted deal is visible to the deal team. Your personal brain is visible to you. None of this depends on a person remembering to set it.
Encryption
Why the Model Looks Like This
We run 60x on 60x. During beta testing, permissions tagging did not work the way we thought it did, and people saw things they should not have seen. Nothing catastrophic, but enough awkward conversations to make the point.
What came out of that was not a better permissions setting. It was a different shape: one shared brain, plus a private brain per person, rather than a single graph with rules layered over it. We only arrived there by onboarding more people and listening to the version of the feedback that started “this was really useful, but I was not comfortable with this”.
Storage and Deployment
The graph runs on a SOC 2 compliant enterprise graph database. 60x is the layer above it: ontology generation, edge criteria, entity extraction, permissions mapping, ingestion and connectors.
You can deploy it inside your own cloud on AWS or GCP, or use a managed service. Neither we nor the database vendor need access to your data for it to work.
The Part People Miss
The two-brain model is not only a privacy control. It is what makes the personal data usable at all.
Once people trust that their inbox stays theirs, they connect it. Once they connect it, the agents working for them get the context that makes their output good: the relationships, the history, the half-promise made on a call in March. A company brain built only from documents that were already shared is a company brain built from the least useful half of what the firm knows.
Related: how every answer is traced and what your firm knew on any date.
Questions You Will Ask
No. Each brain holds separate encryption keys, and personal brains support bring-your-own-key if you want certainty rather than our word for it.
Yes, within their scope. Oversight of a team is one of the things role scoping is for.
No. Write-back is governed separately, with confidence thresholds and a human review queue. The detail is on the trust page.
Yes. Your own cloud on AWS or GCP, your own hardware, or managed by us.
When you next take a demo from any AI knowledge platform, ask where your private context goes and who can read it. Most of them will tell you about their certifications. Ask again about the architecture.