Built to pass your security review, not just your demo.
Tenant isolation, read-only connectors, scoped retrieval, and an immutable audit trail running inside your cloud or your data centre. Nothing leaves your perimeter, and everything the AI does is written down.
Six things that make AI safe to deploy.
Written for the person filling in a vendor questionnaire, not a compliance team reading a framework.
Deployed inside your perimeter
Anvax runs in your AWS, Azure, or GCP account, on a sovereign-cloud partner in your region, or on-prem with no outbound network. We never hold your data. There is no Anvax-side copy to breach.
Read-only connectors by default
Connectors pull documents and records; they do not write back. Write actions are off until an admin enables them per connector, and every enabled write goes through an approval step.
Tenant and workspace isolation
Postgres row-level security and per-tenant encryption keys separate every customer and every workspace. A user cannot surface a document through chat that they could not open directly.
Identity you already run
SSO via SAML/OIDC, SCIM provisioning, role-based access (Owner, Admin, Member, Guest), and per-workspace connector scoping. A finance workstream sees finance systems; a sales workstream does not.
Encryption and key control
TLS 1.3 in transit, per-tenant encryption at rest, customer-managed keys on the private-cloud and on-prem tiers. Secrets for connectors are stored encrypted and never exposed to the model.
No training on your data. Ever.
Models run in your tenant. Prompts, documents, and outputs are not used to train any model, and there is no shared model across customers to leak into.
Three questions every reviewer asks.
Direct answers. No slide decks.
The CISO asks
"What can the AI actually reach?"
Only what the signed-in user can already reach. Every retrieval is permission-checked against the source system's ACLs at query time, not at index time, so a revoked permission takes effect immediately. Connector scope is set per workspace by an admin. On the on-prem tier, egress is blocked at the network layer; the model cannot call out even if prompted to.
The General Counsel asks
"If a regulator asks what the AI said and why, can we answer?"
Yes, from the audit log. Every query records the user, timestamp, the exact documents retrieved (with versions), the model and prompt template used, the answer, and any approvals on write actions. The log is append-only and exportable. This is the same trail we map to SOC 2, ISO 27001, EU AI Act record-keeping, and RBI FREE-AI.
The auditor asks
"Show me a control, not a slide."
Pick one. Retrieval scoping, audit immutability, key custody, and connector write-gating each map to a named control in the framework tabs below, with the implementing component and how to test it. We would rather you test it than trust it.
Honest status. No vanity badges.
We list what is live, what is in progress, and what is mapped. Nothing is claimed that is not implemented.
Six security checkpoints, every query.
Every AI request passes through all six checkpoints in sequence. Select a step to see what it enforces and what it guarantees.
Identity & access
Every request authenticated via SSO (SAML/OIDC) before any AI executes. Sessions are short-lived, phishing-resistant, and bound to your tenant context. No anonymous or shared-credential access at any tier.
Identity verified before any data is touched
Security controls designed for AI, not retrofitted from the last decade.
AI systems introduce attack surfaces that traditional security frameworks were not built for. These controls address each one directly.
Hallucination mitigation
Answers grounded in retrieved context only; model surfaces uncertainty rather than inventing. Every response cites the source it drew from.
PII auto-redaction
PII, names, ID numbers, payment card data, and health identifiers detected and redacted before the model context window is assembled.
Prompt isolation
User input is structurally separated from system instructions; role boundaries enforced at the prompt layer, not relying on model instruction-following alone.
Model pinning
Model version locked per tenant; behaviour cannot change without an explicit upgrade decision and audit entry.
Inference audit
Every prompt, retrieved context, and completion stored in an append-only, cryptographically chained audit log.
Data residency
All inference, embeddings, and retrieval routed within your chosen region. Nothing crosses the perimeter you define.
Spend controls
Per-tenant token budgets with hard limits; anomalous usage patterns trigger alerts before they become incidents.
Human-in-the-loop
High-risk decisions and agentic actions require explicit human sign-off before any downstream action is taken.
Architecture commitments your security team can hold us to.
Questions your procurement team will ask.
Send these to your security team.
Leave your work email and we will send the documents directly. No sales call required for security review.
Architecture report
12-page PDF covering the full defence-in-depth stack, threat model, encryption architecture, and framework control mappings. Send it to your security team before the first call.
DPA and subprocessor list
Data Processing Agreement and subprocessor list for your legal and procurement review. On self-hosted tiers, the subprocessor count is low by design.
Ready for your security team to review us?
Download the architecture report, send us your questionnaire, and we will walk your team through a live deployment.