Your data stays in a dedicated environment in your region, or entirely inside your own cloud.

Never shared, never used to train models. Per-account isolation and full audit trails, built to pass your toughest vendor review.

Last updated 3 October 2026

Explore

Commitments & Controls

Your data stays yours

Promise

Never used to train or fine-tune any model. Leave whenever you want, with everything.

How we do it

Single-tenant: a dedicated environment per client, with its own database, storage, encryption key and compute. Export anytime in Excel or CSV. Full deletion within 30 days of exit, backups included, confirmed in writing.

Private AI

Promise

Your choice of model. Model providers never see your data. No prompts or responses retained.

How we do it

Anthropic, OpenAI or Google models through Amazon Bedrock, Azure OpenAI, Google Vertex AI or your own LLM gateway, on private endpoints in your region. Optional Tacit AI models run entirely inside your environment.

Engineers stay in control

Promise

The AI proposes, your engineers approve. Nothing changes in your records without sign-off.

How we do it

No write access to your systems of record. Every output cites its source evidence. Risk scores are calculated deterministically, so results are reproducible and auditable.

Deploy your way

Promise

Dedicated cloud, your own cloud, on-premise or air-gapped. Your data stays in your region.

How we do it

A dedicated AWS environment, live within days, or your own AWS, Azure or Google Cloud account under your own keys. On-premise or fully air-gapped for classified sites. Residency in the US, EU, UK, Canada, Asia Pacific or South America.

Identity and access

Promise

Your team signs in through your identity provider, under your own policies.

How we do it

SSO with Microsoft Entra ID, Okta, Google Workspace or any OIDC provider. MFA through your IdP or built-in authenticator apps. Granular role-based access, enforced server-side. Tacit AI never sees a password.

Encrypted everywhere

Promise

Encrypted at rest and in transit, under a key that belongs to your environment alone.

How we do it

AES-256 at rest with a dedicated, auto-rotated key per client, or bring your own key. TLS 1.2+ in transit. AI traffic never crosses the public internet.

Every action audited

Promise

Every access, change and approval is logged. When an auditor asks, you have the answer.

How we do it

Full application and infrastructure audit trail, exportable to your SIEM. Web application firewall and continuous threat detection.

Resilience and response

Promise

Your work is protected, recoverable and never dependent on us.

How we do it

Hourly encrypted backups: a one-hour recovery point and a one-business-day rebuild. Security incidents notified within 24 hours. Critical vulnerabilities fixed within 7 days.

Compliance

Promise

Controls aligned to SOC 2 and NIST CSF, with a SOC 2 examination in preparation.

How we do it

Mapped to ISO/IEC 27001:2022 Annex A. GDPR processing under a data processing agreement. AWS is the only sub-processor. Professional liability insured. Your team can audit and penetration-test its own environment.

Compliance & Standards
SOC 2 & NIST CSF Aligned
GDPR
AIAG-VDA
IEC 60812
SAE J1739
ISO 14224
MIL-STD-1629A
40+ Languages

Your security review, ready to go.

Get the full security package under NDA: a control-by-control verification document, our data processing agreement and insurance certificate. Evidence comes from your own environment, never another client’s.

Cookie settings
Necessary cookies keep the site working and are always on. Analytics and advertising cookies are only set if you allow them. You can change this at any time. Privacy policy
Necessary
Allow Necessary cookies.
Analytics
Allow Analytics cookies.
Advertising
Allow Advertising cookies.