HANNA WORKS / SECURITY

Private isn’t a promise.
It’s the architecture.

Your records are read on your infrastructure. Bring the questions your security review would ask. We’ll answer them against a running deployment.

Bring your security questions
THE BOUNDARY

The perimeter
is yours.

One installation for your organisation. Locally hosted models. Access checks enforced in the database.

These protections describe the self-hosted configuration. If you configure an external model endpoint or cloud storage, your chosen provider and network policies define that boundary.

YOUR NETWORK BOUNDARYSelf-hosted configuration
01Your recordsFiles · mail · archives
02Your libraryIndex · access · audit
03Your AILocal inference
Records + question + answerStay inside.
01 / INFERENCE

Your model.
Your hardware.

Local model serving keeps document text and questions inside your network. Model IDs and providers are configuration you control.

02 / RECOVERY

The files remain
the source of truth.

The object store holds the originals. The catalog, extracted fields and search index are derived, and can be rebuilt from those records.

03 / ISOLATION

Access enforced
below the interface.

Database row-level security applies the tenant boundary. Search applies document access before ranking and answering.

06 / CONTROL THAT GOES DEEPER

Trust the answer.
Control the access.

Permissions come first.

Access rules filter the search before documents are ranked. People only receive answers grounded in records they are allowed to see.

Reads leave a record.

Every search and document access can be recorded in an append-only, hash-chained audit trail. Verification detects changes to that trail.

A legal hold takes priority.

A held document cannot be disposed of by a retention schedule, an erasure request or an administrator. Blocked attempts are recorded.

People approve disposal.

Retention rules propose disposal. A person reviews and approves the action before the system destroys anything.

Sensitive fields stay covered.

Configured fields are masked in the interface and exports. A permitted role must explicitly reveal a protected value.

PERMISSIONS, MADE VISIBLE
HR

Employee record

Illustrative record · Sensitivity tier 3
Name
A. Okonkwo
Employee ID
EMP-004182
Base salary
Government identifier
⌑   Restricted
A permitted reviewer can explicitly reveal salary. This viewer cannot.

Document opened. Access recorded.

Audit event

An interactive illustration of access rules. No employee data is connected.

EVIDENCE FOR YOUR REVIEWER

Ask for the proof.
We’ll bring it.

Review the actual mechanisms, configuration and operating procedures behind the claims.

01

A record of who read what and when, with the audit verification tool.

02

The decision log: design choices, dated, with what was measured.

03

The operations manual, backup scope and recovery procedures.

04

An access-isolation test, run against your deployment.

05

Your configuration for sensitivity, retention and field visibility.

06

A walkthrough on your hardware, with your network rules in place.

A CLEAR STATEMENT ON ASSURANCE

Designed for scrutiny. No certification claimed.

There is no SOC 2 report, ISO 27001 certificate or independent penetration-test report being claimed here. If a specific certification is a procurement requirement, raise it on the demo call. Your security team should assess the deployment against your own obligations.

YOUR RECORDS, ANSWERING.

The answer is already
in your records.
Let’s find it.

Start with a library you choose. We’ll size the hardware with you and show you the citation behind every answer.

See it answer your records