Security & Compliance

Enterprise‑grade AI. Enterprise‑grade controls.

Private LLM tenancy, customer‑managed keys, PII redaction, deep audit trails, and every certification your CISO asks for.

Capabilities

Everything you need, nothing you don't.

Customer‑managed keys
BYOK on AWS KMS, GCP KMS or Azure Key Vault. Rotate at will.
Private tenancy
Isolated model instances. No shared inference. No shared training.
Data residency
Pin data to EU, US, or APAC. Regional model deployments.
SSO & SCIM
Okta, Azure AD, Google, OneLogin. Just‑in‑time provisioning.
PII redaction
Named‑entity detection, tokenization and reversible masks.
Audit everywhere
Every prompt, retrieval, decision and send — logged and immutable.
Interface

Trust that passes CISO review.

Documented controls, penetration reports, and evidence for every framework — one portal, always current.

Trust Center
SOC 2 Type II
Independently audited
HIPAA
Independently audited
GDPR
Independently audited
ISO 27001
Independently audited
PCI DSS
Independently audited
CCPA
Independently audited
FedRAMP*
Independently audited
C5*
Independently audited
APRA
Independently audited

* in progress

Why teams love it

Outcomes, not outputs.

01
0 breaches
Since inception. Audited quarterly.
02
99.99% uptime
Multi‑region, active‑active, backed by SLA.
03
Vendor review
Complete a full CISO review in two calls, not two quarters.
04
No data lock‑in
Export raw data on demand. Deletion certified in 30 days.
Inside Security

Enterprise controls, wired in from day one.

Every layer — identity, data, model, network, and audit — is designed for the strictest procurement reviews on the planet.

  1. STEP 01
    Identity & access

    SSO with Okta, Azure AD, Google, Ping; SCIM provisioning; role‑based access down to the row.

    • Passwordless + WebAuthn
    • Just‑in‑time access
    • Session recording for admins
  2. STEP 02
    Data protection

    AES‑256 at rest, TLS 1.3 in transit, customer‑managed keys via AWS KMS, GCP KMS or Azure Key Vault.

    • BYOK / HYOK
    • Field‑level encryption
    • Per‑tenant key isolation
  3. STEP 03
    Model isolation

    Your data trains only your private tenancy. No shared model updates. No cross‑tenant leakage. Ever.

    • Dedicated inference pool
    • Deterministic PII masking
    • Prompt injection defenses
  4. STEP 04
    Network & residency

    Deploy in EU, US, UK, APAC or your own VPC. Data never leaves the region you choose.

    • 12 regions
    • mTLS to your VPC
    • Private link + IP allowlist
  5. STEP 05
    Audit & compliance

    SOC 2 Type II, ISO 27001, HIPAA, GDPR, PCI DSS L1. Every action logged, exportable, and retained per your policy.

    • Immutable audit log
    • Real‑time SIEM streams
    • Vendor review kit ready
Workflow diagram
1. Identity & access2. Data protection3. Model isolation4. Network & residency5. Audit & compliance
Avg. setup
3 weeks
SLA
99.99%
Regions
12
FAQ

Answers, before you ask.

Do you train on our data?+

No — never. Your data trains only your private tenancy, and only when you enable it.

Where is data stored?+

In your chosen region, encrypted with your keys. Backups replicated in the same region only.

Can we run in our VPC?+

Yes — dedicated deployments available for regulated industries.

Give your support team an unfair advantage.

Buy 50 credits. Deploy in a day. Measure lift in your first week.