Security model

Security is where the hardware sits.

Every guarantee on this page is structural — made true by where the deployment runs and what it is physically unable to do, not by a policy document. That is the point of deploying inside your boundary.

the perimeter · sealed
guarantees by architecture
The boundary[01/04]

The perimeter is the product.

01

Nothing egresses

A private deployment has no path out. Prompts, outputs, logs and weights live and die inside your network — there is no phone-home, no usage beacon, no side channel to us.

02

Isolation by architecture

Private planes serve one company; dedicated endpoints serve one customer. Isolation is the shape of the system, not a queue priority or a policy promise.

03

Air-gap friendly

The plane runs without a route to the public internet. Updates arrive as versioned releases you carry across the gap and apply on your schedule.

Data handling[02/04]

Your traffic is not a dataset.

01

Nothing trains on your traffic

Not our models, not anyone's. Serving traffic is serving traffic — it is never retained as a dataset, never sampled for evaluation, never seen by us at all in a private deployment.

02

Your storage, your retention

Request logs and payloads land in storage you own. Retain them for seven years or delete them nightly — the schedule is yours, and deletion means deletion.

03

Keys stay in your vault

API keys are minted, scoped, rotated and revoked inside the boundary. Storage credentials and model weights follow the same rule: we operate software, never your secrets.

04

Audit-grade accounting

Every request is logged and attributable — who called, what model, when, at what cost. Exportable to the tooling your auditors already use.

From outside the boundary[03/04]

This is our view of your traffic.

Not encrypted-but-visible. Not anonymised. Unreachable — the deployment shape leaves nothing on our side of the wall to read.

no prompts · no outputs · no telemetry — redacted by design
Operations[04/04]

Boring on purpose.

Versioned releases

Updates ship as signed, versioned releases with changelogs. You review, you schedule, you apply — nothing updates itself inside your boundary.

Least-privilege operations

For dedicated endpoints we operate the plane with scoped operational access — never access to your prompts, outputs or keys.

Something to report?

If you believe you've found a security issue in anything we ship, contact our team — it goes straight to the people who build the plane.

Security questionnaire coming your way? Send it over.Contact our team →