olee four products
Products Pricing Security About Contact Sign in
Security
Separation you can check, not separation you have to trust.
Four products, four databases, and a separate account for each. Here is what that means in practice, and what we do not claim.
Isolation is in the database
Every table holding client data carries a row-level security policy, so a query has to satisfy Postgres as well as the application. A bug in our code is not enough to show one client another client's rows.
Four products, four databases
Each product keeps its own accounts, its own billing and its own database, behind its own policies.
Signing in proves who, the product decides whether
Signing in proves identity. The product then checks that this person belongs to an organisation with access to it, because anyone can type a product's address.
Nothing trains a model
Your content is sent to an AI provider to answer the request in front of it and for nothing else. We use paid API tiers where training on customer content is off by contract, not by a setting we could forget.
In practice
The specifics, rather than the adjectives.
Access and accounts
Passwords are hashed by the auth provider; we never see one.
Creating an account needs an invitation code, on every product.
An operator flag lives in one row in one table and is revocable, it is not an email address hardcoded into a product's source.
Product-to-product calls carry a per-product secret compared inside the database, so the stored hash never leaves it.
Data handling
Encrypted in transit, and at rest by the storage provider.
Delete a document and everything derived from it, extracted fields, indexed passages, generated summaries, is deleted with it.
Backups roll off on their own schedule and are fully replaced within 35 days of a deletion.
Retention windows are set per organisation, within limits, and a record is deleted at the end of one rather than archived.
Operations
Administrative changes are written to an audit log the person who made them cannot edit.
Bot protection on sign-in and on every public form.
Security headers, a content security policy and framing denial on every product surface except the widgets meant to be embedded.
Payments go to Stripe. Card numbers never reach our servers.
What we do not claim.
A security page is worth reading only if it is willing to say where the line is.
No certification
We hold no ISO 27001, no SOC 2. Nobody has audited us against either, and we will not imply otherwise.
No uptime guarantee
Unless one is written into your contract. We publish what we know when something is wrong.
AI output is not guaranteed correct
Confidence scores and citations exist precisely because it is not.
Found something?
Report it to hi@olee.ai. We answer within two working days, we will not threaten you for telling us, and we will credit you if you would like us to. Please do not test against a live client's workspace. Ask us and we will give you somewhere to test.
The rest of them
Each one has its own account.
OleonAnswers customers on WhatsApp and your website, sells, and hands over to your team when it cannot. OleeHirePosts jobs, screens the CVs that arrive, and interviews the people you shortlist. OleeVisionReads IDs, invoices and forms, and gives back clean fields you can use. OleeLawSearches Sri Lankan case law by the situation, and drafts the deed or the plaint that follows.
Pick one, and have it running this week.
Documents read into clean fields, a shortlist instead of a pile, customers answered while you sleep, or the case law found. Start with the one you need.
Start with OleeVision Start with OleeHire Start with Oleon Start with OleeLaw