Security & data handling

Built for the room that says no.

01

Zero egress by default

Source copybooks, generated schemas, and policy data never leave your network. The engine runs inside your VPC on your hardware. There is no outbound call to make — no SaaS backend, no third-party LLM, no analytics endpoint.

0 bytes out
02

Local model, on-prem

Drafting runs on a local model (e.g. Gemma-class) on your own GPUs. No prompt, no field, no copybook fragment is ever sent to an external API. The model is shown only the deterministic AST — never your raw data in transit.

your GPUs
03

No telemetry, no logs that leave

No usage telemetry, no cookies on the engine, no prompt logs shipped off-box. What runs in your perimeter stays in your perimeter. Audit logs are written to your storage, under your retention policy.

no telemetry
04

Deterministic & reproducible

Same input, same output, every run — no temperature, no sampling drift. Every transformation is hashed (SHA-256 input and output). Your security team can re-run any receipt and confirm the hashes independently.

SHA-256
05

Two-model consensus, not blind trust

When a parity or structural gate fails, recovery requires two independent models to agree (≥0.95) before any output emits. No single model gets the last word, and nothing ships that hasn't passed every gate.

≥0.95 agree
06

Solo-built is a control, not a risk

No sprawling vendor with a hundred sub-processors. A focused, air-gappable engine with a small, auditable surface is easier for your security team to reason about than a cloud platform you have to take on faith.

small surface
0 bytes egressno third-party LLMno telemetryno prompt logsSHA-256 receiptsruns in your VPCair-gappable

Want the air-gapped build for an internal security review? Request it here — we'll scope a deployment inside your perimeter. Your team can read the verification engine source and reproduce every receipt first.