The posture is solid for enterprise review. It is SOC 2 compliant with end-to-end encryption, RBAC, SAML SSO, SCIM provisioning, audit logs and GDPR/CCPA, and it states that customer data is not used to train public models, usually infosec's first question about any AI tool. Have your data-handling and access requirements written down before the call, and expect to hand their security packet to your compliance team.
our security lead wont even look at an ai tool unless no training on our data is explicit in the contract. inventive checked that box for us
One thing to watch is your own internal permissions. If you connect the whole drive without limits, people could search folders they shouldnt. platforms fine, thats on your setup