Run AI security entirely inside your own boundary. No outbound connections, no telemetry, no vendor dependency at runtime — and an audit trail that survives a records request.
The engine and a local dashboard run with no outbound connections at all. Licensing is verified offline with signed cryptographic licences, so an isolated network never needs to reach us — not even to stay licensed.
Self-hosted or air-gapped, prompts and documents are processed inside your infrastructure. Data residency is a property of where you deployed it, not a promise about our regions.
Defends the case that matters for automation: an untrusted document or web page that tries to redirect an agent into an action nobody authorised. Capability containment gates the action, not just the text.
Detect and redact personal identifiers in the request path, so sensitive constituent data is removed before it reaches any language model.
Authentication, authorization, configuration change and security events are recorded with actor, outcome and severity — the record a FOIA response, an inspector general or an internal review actually needs.
SAML and OIDC single sign-on with your existing identity provider, SCIM directory sync so departures revoke access automatically, and four-role access control enforced server-side.
Docker Compose or the Helm chart, on infrastructure you control. No inbound access from us is required or possible.
A signed licence file is validated locally. There is no activation call and no heartbeat, because an air-gapped network cannot make one.
Change a base URL, or use the SDK. Scanning happens locally against your policies.
Watch the network. Nothing leaves. That is a property you can confirm rather than a claim you have to accept — and we will support you doing exactly that as part of a security review.
We do not hold FedRAMP authorization — see our security page for exactly what we do and do not have, then tell us what your authorization process requires.