Your model.
Your hardware.
Local model serving keeps document text and questions inside your network. Model IDs and providers are configuration you control.
Your records are read on your infrastructure. Bring the questions your security review would ask. We’ll answer them against a running deployment.
Bring your security questionsOne installation for your organisation. Locally hosted models. Access checks enforced in the database.
These protections describe the self-hosted configuration. If you configure an external model endpoint or cloud storage, your chosen provider and network policies define that boundary.
Local model serving keeps document text and questions inside your network. Model IDs and providers are configuration you control.
The object store holds the originals. The catalog, extracted fields and search index are derived, and can be rebuilt from those records.
Database row-level security applies the tenant boundary. Search applies document access before ranking and answering.
Access rules filter the search before documents are ranked. People only receive answers grounded in records they are allowed to see.
Every search and document access can be recorded in an append-only, hash-chained audit trail. Verification detects changes to that trail.
A held document cannot be disposed of by a retention schedule, an erasure request or an administrator. Blocked attempts are recorded.
Retention rules propose disposal. A person reviews and approves the action before the system destroys anything.
Configured fields are masked in the interface and exports. A permitted role must explicitly reveal a protected value.
Document opened. Access recorded.
Audit eventAn interactive illustration of access rules. No employee data is connected.
Review the actual mechanisms, configuration and operating procedures behind the claims.
A record of who read what and when, with the audit verification tool.
The decision log: design choices, dated, with what was measured.
The operations manual, backup scope and recovery procedures.
An access-isolation test, run against your deployment.
Your configuration for sensitivity, retention and field visibility.
A walkthrough on your hardware, with your network rules in place.
There is no SOC 2 report, ISO 27001 certificate or independent penetration-test report being claimed here. If a specific certification is a procurement requirement, raise it on the demo call. Your security team should assess the deployment against your own obligations.
Start with a library you choose. We’ll size the hardware with you and show you the citation behind every answer.
See it answer your records