Security / Architecture whitepaper

The full architecture, for the people who have to sign off

Deployment topology, isolation boundaries, key handling, and the control mapping. Watermarked, shared under NDA, and written for reviewers rather than buyers.

Security overview

Contents

What is inside

Seven sections, roughly forty pages, with diagrams your infrastructure team can build against. We do not publish it because the deployment detail of a client enclave is not public information.

  • 01Deployment topology

    Node specification, network placement, and how the enclave sits inside your existing segmentation.

  • 02Isolation boundaries

    Process, namespace, and storage separation between the runtime, the index, and the corpus.

  • 03Key handling

    Where keys are generated, where they are held, and what happens to them at teardown.

  • 04Retrieval and privilege

    How classification is applied at ingest and enforced before inference reaches a passage.

  • 05Agent execution

    Namespace restrictions inherited by background jobs, and why an agent cannot exceed the session.

  • 06Control mapping

    Each guarantee mapped to the GDPR, HIPAA, and SOC 2 control it addresses.

  • 07Upgrade and teardown

    Model updates in place, RAM wipe on teardown, and the evidence produced by each.

Who we send it to

Chief information security officers

The isolation model, the threat cases we designed against, and what we deliberately did not build.

Infrastructure teams

Hardware requirements, provisioning, and where the enclave touches your network.

Outside counsel and client auditors

The control mapping and the data handling statement, ready to attach to a security questionnaire.

Ask for the document, not the sales deck.

Tell us who is reviewing and we will send the whitepaper under NDA, then walk it with them.