Security

Controls your IT team will recognise.

Identity, access and audit are how the product works, not an enterprise tier added later. Every row below is shipped behaviour.

Private betaQuestionnaires answered in writing
01 · Identity

Access is provisioned, not accumulated.

Single sign-on
OIDC and SAML 2.0. Domain verification over DNS TXT.
Provisioning
SCIM with bearer tokens. Your identity provider's groups map to roles.
Authentication
2FA over TOTP with backup codes. Google and GitHub sign-in. Sessions reviewable in user settings.
Roles
Six built in, plus custom roles and access groups with a permission matrix.
OwnerAdminBillingMemberViewerGuest
Ownership
Exactly one Primary Owner. Ownership transfers; it never disappears. Owner-only: roles, billing, SSO, deletion.
02 · Platform

Scoped keys. Explicit allow lists.

API keys
Prefixed neoiq_, shown once at creation, scoped by preset, and expiring — 90 days by default.
Key presets
Administrator, Standard, Read Only, CI/CD, Full Access, Custom.
Integrations
Model Context Protocol servers scoped to System, Organization or User, with an explicit URL allow list and per-server auth.
Model providers
Your own keys for OpenAI, Anthropic, Google, Mistral, Azure or AWS. Overage capped in USD per month. Full usage exports as CSV.
Deletion
Deleting an organization takes two steps — the typed name plus a six-digit email code — and only the Primary Owner can do it.
03 · Audit

Every decision has a name on it.

Attribution
Every rule change, verdict and shipped output carries the operator who approved it.
Overrides
A soft block can be overridden — with a written reason, logged against a name.
Organization log
Membership changes, key creation, integrations and approvals in one record.
Export
Usage and the audit trail export as CSV — model, provider, tokens, requests, estimated cost.
The gate

Most work passes. The gate is for the rest.

Brand Guard sits between drafted and ready. It does not rewrite the work — it names what would fail review and holds it there, so an operator decides.

Brand Guard rules v14

Every draft is checked before it can be marked ready. A hold names the rule and the edit that clears it; an override needs a written reason, logged against a name.

  • KV-03 · EN headline
    Ready
  • KV-03 · AR headline
    Register · reads MSA, approved work is khaleeji
  • Launch film · 30s cutdown
    Ready
  • OOH · 6-sheet
    Ready
  • Press ad · claim line
    Claims · superlative not substantiated
  • Social · eight sizes
    Ready

Sample artefacts · a product view

Not there yet

NeoIQ is in private beta, and these are the questions procurement asks that we cannot answer on a web page today. Ask us and we answer in writing — including what is shipped and what is still on the roadmap. Talk to our team.

  • SOC 2 · ISO 27001 status
  • Data residency and hosting region
  • Retention and deletion timelines
  • Tenancy and isolation model
  • Whether tenant data trains models
  • Uptime commitment and SLA
  • Subprocessor list and DPA
  • Penetration test results