Security architecture, stated the way we would defend it
Every control on these pages is described in plain language, with its current status and known limitations. No badges, no implied certifications — architecture you can put in front of a security team.
Security topics
Data boundary
The platform is designed so that raw enterprise data does not leave your environment. Models, documents, embeddings and answers live on infrastruct…
Read →Identity and access
Access follows your identity provider and your role model. Permissions are enforced where it matters — inside the retrieval query — so users can on…
Read →Audit and evidence
Regulated operations must be able to prove what the system knew, which policy applied and why an answer was produced. Evidence is a first-class out…
Read →Knowledge governance
What the AI is allowed to know is a governed decision, not a side effect of what happens to be on the file share.
Read →Model governance
Local determines where AI runs. Governance determines whether it is safe, grounded and approved. Models, embeddings, retrieval configurations and p…
Read →Resilience and rollback
A governed system must be stoppable, restorable and reversible. These properties are drilled, not assumed.
Read →Responsible disclosure
How to report a vulnerability to mAIb Tech, what to expect from us, and what is in scope.
Read →Where we are honest about maturity
mAIb Tech is pre-certification: no issued certification is claimed. The Trust Centre separates what is implemented, what is tested, and what is on the roadmap — and the framework alignment page states our position per framework without implying approval.