Sovereignty

Growth you own. Data you keep.

InRoots is built to be run by you. Every design decision below exists so that people data stays inside your walls.

Bring your own model

Sixteen providers are supported, including Anthropic, OpenAI, Gemini, Mistral, Groq, DeepSeek, Cohere and Hugging Face, and a local Ollama. Point InRoots at a local model and standup text never touches a public API.

Data flow

  • Input: chat messages from your Matrix server, or bridged Slack and Teams workspaces
  • Processing: parsing, scoring and coaching run inside the InRoots container on your infrastructure
  • Storage: SQLite or Postgres, yours
  • Output: dashboards, direct messages, exports and the webhooks you configure
  • Nothing else leaves: no telemetry, no usage beacons, no crash reporters calling out

Offline geo and IP intelligence

A bundled GeoLite database classifies office, home and mobile on-host. Location is consent-gated and visible to the employee it concerns.

Consent and audit

Policies are versioned and e-signed with a tamper-evident hash. Every decision, weight change and auto-approval lands in an audit log that admins can export.

Access control

  • Five roles: employee, team lead, manager, admin, superadmin
  • One-time codes for sign-in, trusted-device sessions, personal API tokens
  • Single sign-on available on enterprise and self-hosted deployments
  • Integration credentials encrypted at rest with a key you hold

Reporting a vulnerability

Write to security@inroots.ai. We acknowledge reports and keep reporters informed until the issue is closed. Public certifications are listed here only once they are issued; we do not display badges we do not hold.