Timberline is built for organizations that cannot treat sensitive information casually. Customer data is used to provide the service to your organization—not to train shared models, not to improve another customer’s experience, and not to become part of a shared data pool.
Customer information is never used to train shared models or improve the service for other customers.
Model trainingOff
Private by default
Work stays private to the people who are given access.
Visibility: Private
Controlled access
Invitations, SSO or MFA sign-in, and permissions decide who can enter and what they can see.
SSO or MFACare ManagementCompliance
Defined retention
Administrators set how long chats are kept.
Chat retention · 90 daysAdmin control
Controlled connections
External systems are connected deliberately and scoped to their intended use.
Connected systemScoped
Tenant isolation
Your environment is separated from every other Timberline customer.
Dedicated keysAES-256 at rest
What happens to your data.
From the moment information enters Timberline to the day it is deleted, it is handled inside your organization’s environment, under the controls you set.
01Sources
ChatsUploadsConnected systemsScoped
Signed in with SSO
02Processing
Private inference · Your Timberline environmentPublic model API
03Encryption & access
TLS 1.2+ in transitAES-256 at restDedicated keys
Access
Care ManagementCompliance
Only people you give access
04Chat retention
90 days30 daysAdmin control
When it comes in
Information enters through your team’s chats, uploads, and the systems you choose to connect. Only invited members of your organization can add to the workspace, signing in through your SSO or with a password and multi-factor authentication, and each connection is scoped to its intended use.
While it’s in use
Prompts and documents are processed with private inference inside your isolated Timberline environment. They are not sent to a public third-party model API, and they are never used to train models. If an administrator enables web search, only the search query goes out, with identifying details removed first.
While it’s stored
Chats, projects, and documents are encrypted in transit with TLS 1.2+ and at rest with AES-256, using keys dedicated to your organization. They are visible only to the people you give access.
When it’s removed
You decide how long chats are kept. Chat retention is configurable through administrative controls, so your organization sets the period that fits its policies.