Nothing leaves the node
The model, the index, and the documents share one machine boundary. There is no inference call to a vendor, no telemetry payload, and no cache outside the enclave.
Platform overview
Sanctum Lex is one system: a sealed runtime, a matter aware repository, and a set of agents that work the file without ever moving it. Deployed inside your perimeter and governed by your policy.

The model, the index, and the documents share one machine boundary. There is no inference call to a vendor, no telemetry payload, and no cache outside the enclave.
Every passage returned names the file, the page, and the matter it came from, so a partner can check the work before it reaches a client.
Classification is applied at ingest and enforced at retrieval. A privileged document cannot surface in a workspace that is not cleared for it.
The system
Each module is useful on its own and stronger together. None of them require a document to leave the machine it was ingested on.
Ecosystem
Connectors read in place and respect the permissions already set on the source. Nothing is duplicated into a vendor cloud to make search work.
Controls
Sanctum Lex is designed to align with GDPR, HIPAA and SOC 2 standards. SAML single sign on, scoped audit logs, IP allow lists, and retention rules are on by default.
More about securityWe walk the architecture, open the audit log, and run the system against documents you choose.