The governed private AI platform
Three layers turn a capable model into a system a regulated enterprise can defend: private infrastructure, governed knowledge and execution, and verifiable evidence.
Private infrastructure
The platform installs inside your environment — there is no vendor cloud behind it, no external account, and no telemetry.
Customer-controlled deployment
Hardened container package on your servers: on-premises, private cloud, Kubernetes, or fully air-gapped. Signed, verifiable update paths — including offline transfer.
Approved models, no lock-in
A model-adapter layer keeps the platform model-neutral: open-weight defaults or a customer-provided endpoint. Model changes are governed changes.
Controlled connectors
Read-only ingestion from SharePoint/M365, ServiceNow and file systems, preserving source access controls fail-closed.
Data residency by construction
Documents, embeddings, answers and audit records live on your infrastructure. Residency follows your decisions, not ours.
Network-boundary enforcement
Raw enterprise data egress is zero by design — enforceable at your own network boundary in on-premises and air-gapped deployments.
Customer-held keys
Encryption with a documented key lifecycle; customer-held keys supported where the deployment model allows, with HSM/TPM/Key Vault as documented integration seams.
Governed knowledge & execution
What the AI knows, who may ask what, and what it may say are governed decisions with named approvers — not side effects.
Source approval
Only designated repositories feed the system; ingested content becomes a draft until a human approves it.
Classification & redaction
Deterministic detectors block documents containing secrets outright; sensitive identifiers are masked before any embedding.
Versioning & rollback
Knowledge ships as versioned packs with provenance and permissions; every activation can roll back to the previous approved state.
Permissions in-query
Role-based access enforced inside retrieval queries: no prompt can surface knowledge the user is not entitled to see.
Human approval gates
Knowledge activations, model swaps and baseline changes pass approval gates; go-live decisions fail closed.
Policy controls
Advisory-only output with dangerous-action refusal, confidence scores and risk labels on every answer.
Verifiable evidence
Evidence is a first-class output: the system is designed so that what it knew, who approved it, and why it answered can be reconstructed later.
Audit events
An append-only, hash-chained audit trail records questions, answers, approvals and administrative actions; security events forward to your SIEM.
Provenance & decision records
Every answer carries citations and the knowledge version used; approvals record who decided what, when.
Evidence export
Exportable evidence packs designed for security review, internal audit and renewal decisions — counts and durations by default, never raw content.