Deployment models
The platform deploys three ways: managed cloud, dedicated single-tenant environments, and sovereign or on-premise installations for customers with data residency requirements. The decision model, not the data, is the product: deployments are designed so that operational data stays within the boundary the customer chooses.
Data segregation and access
Customer environments are segregated by tenant. Access follows least privilege: production data is accessible only to the roles that operate the relevant environment, and administrative access is logged. Credentials and secrets are managed through dedicated infrastructure rather than embedded in code.
Encryption
Data is encrypted in transit using TLS and at rest using the encryption facilities of the underlying managed infrastructure.
Model training boundaries
Customer operational data is used to run and calibrate that customer's own deployment. It is not used to train models shared across customers.
Residency and sovereignty
For sovereign and regulated deployments, the platform supports in-country hosting and customer-controlled infrastructure, with data residency defined contractually and enforced architecturally.
Continuity and incident handling
Deployments are designed for graceful degradation: optimization layers fail toward safe defaults rather than hard stops. Incidents follow a defined response process with customer notification obligations set in the underlying agreements.
Responsible disclosure
If you believe you have found a security issue on this website or in the platform, submit the details through the engagement page and select Other as the topic. Do not test against production systems that are not yours.
Formal documentation
Detailed security documentation, architecture reviews, and diligence responses are available to qualified counterparties under NDA through the engagement page.
