███╗   ███╗ ██╗   ██╗  ██████╗ ███████╗ ██╗
████╗ ████║ ╚██╗ ██╔╝ ██╔════╝ ██╔════╝ ██║
██╔████╔██║  ╚████╔╝  ██║      █████╗   ██║
██║╚██╔╝██║   ╚██╔╝   ██║      ██╔══╝   ██║
██║ ╚═╝ ██║    ██║    ╚██████╗ ███████╗ ███████╗
╚═╝     ╚═╝    ╚═╝     ╚═════╝ ╚══════╝ ╚══════╝
Star
Changelog
  • kernel
  • fix

Your knowledge stays yours

Found by an audit, before a customer found it.

Every API route scoped uploads and answers to the business that wrote them. The one place that puts those files in front of the agent did not. So two businesses running the same wedge shared a pile: uploaded documents, intake answers, prices, policies, and past corrections.

It was not only a disclosure. Intake answers use the same filename for everyone, so the last business to answer a question quietly overwrote everyone else's answer. Your agent could quote a stranger's late fee to your client, and nothing anywhere would say why.

Reading knowledge now requires a business id and fails closed. An unlabelled row belongs to nobody rather than to everybody.

Also: what we charge you was measured wrong, by 15-60x. The meter used hardcoded prices from a different model provider than the one we run. The free tier's "$2 a month" of usage was really about three cents. It reads the real price table now — which is the same number the plan ceiling enforces, so the limits mean what they say.