AI Security

Vector Database Access Control Checker

Audit the access controls around a vector index, covering tenant isolation, whether filtering happens before or after search, deletion reach, and the exposure created by storing document text alongside embeddings.

Last reviewed by the Radiatus Cloud team

Results appear here.

Securing AI in production?

We build guardrails, governance & compliance for AI systems.

Talk to an AI advisor

The filter has to be inside the query

Retrieval systems are usually built single-tenant and made multi-tenant later, and the natural place to add a permission check at that point is after the results come back. That is too late. The content has already entered the model context, and by the time an unauthorised document is filtered out of the result list, it may have been summarised, paraphrased or reasoned about in the response. The check belongs in the query that fetches the vectors, so unauthorised material is never retrieved at all.

An embedding is not an anonymised document

It is tempting to treat a vector as an opaque array of floats and therefore as safe. Published inversion work recovers substantial portions of the original text from embeddings alone, and most deployments additionally store the chunk text in the payload for citation purposes, which makes the question moot. An exposed vector index is much closer to an exposed document store than to a store of hashes, and it usually carries none of the source system's access control unless that was deliberately rebuilt.

Deletion has to reach the index

When a record is deleted from a source system, the corresponding vectors and payloads frequently survive, because the deletion path was built before the index existed. The result is a system that has honoured an erasure request in the database and continues to answer questions about the person from the index. Backups compound it: a restore that predates the deletion reinstates the data, and nothing in the process notices.

Related tools

Frequently Asked Questions

Why does post-filtering not work?

Because the content has already reached the model context and may be summarised into the answer. Removing the document from the result list removes the document, not the disclosure.

Are embeddings anonymous?

No. Published inversion work recovers substantial portions of the original text from vectors alone, and most deployments also store the chunk text for citation, which settles the question.

Should each tenant get its own namespace?

Where the engine supports it, yes, because physical separation fails safe. An omitted metadata filter returns everything; an unaddressed namespace returns nothing.

What is the difference between pre-filter and post-filter?

Pre-filter restricts the candidate set before approximate search; post-filter removes results afterwards, which silently reduces recall and can return fewer results than actually match.

Does erasure reach the vector store?

It has to. A record deleted from the source but still embedded remains retrievable and still answers questions about the person, and a backup restored past the deletion reinstates it.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Tick the controls in place to score the vector store.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.