Skip to content

Security FAQ

Answers procurement and security teams ask first.

Factual responses for vendor reviews. If something is not yet attested, we say so, rather than inventing certifications or partnership claims.

FAQ

Data, tenancy & models

No. Production programs target your cloud estate. We do not operate a shared InheritX product that trains public models on your proprietary data.

Depending on architecture choices: commercial APIs (e.g., OpenAI, Anthropic, Google) and/or models hosted in your VPC. Provider selection is part of blueprint, and governed by those providers’ terms plus your policies.

No. They indicate platforms and models we commonly implement with. Formal partnership status is only claimed when a contract exists; ask us for current status in diligence.

Yes when the architecture calls for private endpoints, VPC-hosted models, or approved private networking patterns. That choice is designed in blueprint, not bolted on after a demo.

FAQ

Access, logging & offboarding

Through identities and roles you approve, preferably time-bound and least-privilege, following your IAM and change processes.

We design for attributable traces on agent/tool actions and generation workflows, with retention aligned to your policy. Exact tooling is chosen per estate.

Access is revoked per your offboarding checklist; repositories and runbooks remain under your control as defined in the handover package.

Formal SOC/ISO marks are published only when evidenced. Until then, use this Security FAQ and the Diligence Pack under NDA. We share attestation status factually during vendor review, this site does not claim certifications that are not currently evidenced.

Capabilities

Anonymized engagement classes (from published cases)

Derived from published case studies, not invented client names. Use these for early peer matching; named references require written approval.

Healthcare & clinical workflows

Published patterns in intake, vision quality gates, and care discovery. Cases: AI Dent, Heva.

AI platforms & LLMOps reliability

Published work hardening AI builder infrastructure and recovery. Case: Kavia AI.

AI infrastructure security

Published posture hardening for an AI damage-detection platform. Case: T2D2.

Enterprise operations systems

Published multi-property and real-time operations platforms. Cases: QDIS, Twelfthman, E-mobility.

Perspective

What we share publicly vs under NDA

Named customer quotes are anonymized until written approval is on file. Public materials include this FAQ, published case methodology, anonymized engagement classes from those stories, and company pages on security practices and IP ownership.

Named customer references: only with written approval. Otherwise anonymized industry + scale references under NDA for qualified opportunities, after a strategy or security diligence conversation confirms fit.

Next step

Map this capability to your mandate.

A focused strategy conversation, constraints, systems, and what production readiness looks like for your organization.