org.tech/Governance/What we do not claimThe glass-box page.Exact beats broad
Anything we leave vague here, you would find later, at a worse moment, with less goodwill.
The limits, in writing.Read these first.
Every other page on this site states what is true. This one states what is not. It is not a legal hedge and it is not modesty. A claim you can check is worth more than a claim that sounds bigger, and the only way to be checkable is to draw the edge yourself.
The first set of limits is about evidence of the ordinary commercial kind. We are a young practice and we have not accumulated the artifacts that make a vendor comfortable to buy, so here they are, absent, in one place.
What stands in their place is evidence you can check yourself: a controls matrix with verdicts, a deployment in an account you own, and the standing exceptions rendered to you inside the product.
No managed frontier model runs inside anyone's network, ours included.
This is the limit most often blurred in this market, usually by people who know better. Getting it right is the difference between a claim your security reviewer accepts and one they stop reading at.
01
"The AI runs inside your network." It does not. The compute, the storage, the identity and the policy are in an account you own. The model is reached as a managed service, and its fleet belongs to the provider.
02
"Data never leaves your boundary." Data at rest stays in your account. The content of an inference call is processed by the managed model service, under your account's retention election.
03
"Your data never leaves the country." Only under a residency pin, and not for every model. Unless pinned, the default routing may process a request in another region.
04
"A tunnel into your office network." The platform lives in a cloud account you own and your people reach it by signing in. There is no VPN, tunnel or reverse proxy from it into your office network.
The costEvery current frontier model routes outside CanadaPinning is a real capability tradeoff, chosen on purpose
Generated, never typed·Refused in words, never rerouted
Three things the logs will not tell you.
RECORDS · WHAT THEY DO NOT CONTAIN
A record that is described loosely is worse than no record, because somebody will rely on it in an investigation. These three are the ones most often overstated in AI governance material.
01 Deployed
No prompt or answer text.
The model invocation log carries model, caller identity, latency and token counts, and deliberately no content. So we never write that every prompt and response is auditable. It is evidence of use and attribution, which is a different and more defensible thing.
We publish no availability number, no response-time commitment, no latency figure and no time-to-deploy figure, for one reason: we have not measured any of them to a standard we would defend in front of a reviewer. There is no timer in the deployment factory and no service-level objective anywhere. Rather than borrow a plausible number, we leave the space empty.
The same discipline applies to operations. What exists is deliberate: releases rolled one deployment at a time and confirmed, drift and diff checks before changes, acceptance scripts run against the live deployment over HTTPS, a dated operations journal, and a direct line to the person who built it. What does not exist, and is therefore not sold to you: an error budget, an on-call rotation, an incident severity classification and a paging configuration.
Baseline, stated without softening
Baseline is the low-cost entry posture. It has no private networking and no account-level audit trail, and encryption at rest uses provider-owned keys. It suits low-sensitivity use and a first evaluation. A security review will usually want Standard, and we will tell you that before you buy rather than after the questionnaire comes back. See posture tiers.
Built, working, and not yet proven at your scale.
MODULES AND EXIT · THE HEDGES
01
Client modules in use today run on the staging channel.Pilot The production promotion path is built and exercised on our own deployment, by hash, approved by a named administrator.
02
Client-authored modules are a pilot. The authoring path is proven end to end by us acting as the client, and the first client-authored build is a pilot rather than a routine.
03
Two administrators approve a promotion. A single-administrator deployment can self-approve with a written justification, recorded verbatim as exactly that. It is not segregation of duties and we never call it that.
04
Moving to another cloud would be a rebuild. The platform is deeply built on one provider. "Composable" in our copy refers to models: switching a model is configuration, not a migration. It has never meant clouds.
05
Keeping the platform is not the same as running it. If the service stops you keep the deployed platform, its data and its source. Operating it afterwards needs a competent cloud engineer, which is why runbooks and infrastructure as code are deliverables.
What you may have read, and what is true here.
CORRECTIONS · INCLUDING OUR OWN
The claims in the left-hand column are the boilerplate of this market. Each one is corrected against what is actually true of a deployment, with the page that carries the detail.
What you may have read elsewhere
What is actually true here
Read more
"The AI runs inside your network."
A managed model service cannot run in your network. Your compute, storage, identity and policy are in an account you own; the model is reached as a service.
Residency is configurable and pinned to your region when you need it. Under the pin, every current frontier model has no route and is refused in words rather than rerouted.
The platform lives in a cloud account you own and your people reach it by signing in. No VPN, tunnel or reverse proxy into an office network is part of it.
We hold no third-party attestation. We provide technical controls designed to align with SOC 2 Trust Services Criteria and ISO/IEC 27001:2022 Annex A, each with a verdict.
The rule we work to: exact claims beat broad claims, and region, model, retention, networking and provider behaviour all have to be specified before a sentence about them is true.
The exact claim is the useful one.
WHY THIS PAGE EXISTS
A broad claim protects the seller. An exact claim protects the buyer, because it is the only kind you can carry into a room and answer for. When your board asks whether the AI environment is under control, "it is private and secure" gets you nothing. "Inference cannot happen without the content policy, it is confined to these regions, the knowledge base has no per-document permissions so we load only what everyone may see, and here is the list of what is not closed" ends the conversation properly.
It's not a black box. You can see how it's set up, and that's exactly what lets you answer for it.Why the limits are published next to the claims
Some, and it ends the wrong ones early, which a practice this size cannot afford to do slowly. The buyers we want are the ones who read this page and recognise the register, because it is the same register we will use during an incident.
02Will this page change?
Yes, by deletion. When something here becomes true it moves to the page that describes it, and this page loses a line. What we will not do is pre-announce: if a capability is not built, it does not appear on this site at all, including as a roadmap item.
03If the model is not in our network, what exactly is private?
The account, the identity directory, the data at rest, the knowledge index, the roles and grants, the audit records, the encryption keys at the higher tiers, and the policy that every inference call must carry. Most "private AI" means a vendor holds your data privately. Ours means you hold it.
The honest way to say the rest: the content of a model call is processed by the managed model service, under your account's retention election, and by default prompts are not used to train models and are not shared with model vendors.
04Do the same limits apply to the knowledge gateway?
No. It is a different product with a different shape: a private server in a cloud account you own, giving the assistant your people already use governed access to your documents. It runs no language model, and tool results travel to that assistant's vendor, which is its own boundary question. Its limits are set out at gateway limits.
⎯⎯ Book the strategic assessment ⎯⎯
Your private AI, inside your control ·
Bring the hardest item on this page to the assessment and we will tell you whether it is a blocker for you or not.