Security architecture

Verify the architecture. Don't take our word for it.


No internet egress. Per-user encryption. No standing access to your data.

Every security claim on this page is an architectural constraint, not a policy promise. Your security team can verify each one independently.

Six isolation layers. No outbound route. Encrypted per user.

Security principles

Three constraints enforced by infrastructure

These are structural properties of the environment, not policy toggles. Changing any of them requires rebuilding the infrastructure. Any exception requires explicit change control and leaves an audit trail.

No internet egress

No internet gateway. No NAT gateway. No public IP addresses. No route to 0.0.0.0/0. Traffic cannot leave the boundary because there is no path out. Verified by route table inspection, not by reading a policy document.

Per-user encryption

Every user's chat data is encrypted with a unique key. In the SaaS environment, there is no single master key that can decrypt all users. In Enterprise, your organization owns the key hierarchy and your admins control access to every user's keys through your own processes. The encryption architecture is documented in full during the security review.

No standing access to your data

On Enterprise, no one at TPAI has persistent access to your production environment. Emergency access requires a documented request, MFA, your approval, and expires after one hour with a full audit trail. On Pro, TPAI operators maintain the infrastructure but do not access your encrypted chat data.

Defense in depth

Six isolation layers. Defense in depth.

The environment is protected by six layers of network and access controls, spanning network architecture, traffic rules, routing, private service endpoints, and organizational guardrails. The full architecture walkthrough is available under NDA as part of our security review.

1

Network boundaries

Private subnets only. No internet gateway. No NAT gateway. No public IP addresses anywhere in the environment.

2

Network-level rules

Deny-all defaults at the subnet level. Only explicitly allowed traffic between internal services passes through.

3

Service-level rules

Per-resource firewall rules with tightly scoped ingress and egress. No default "allow all" posture anywhere in the stack.

4

Routing controls

No default route to the public internet. Traffic can only reach internal endpoints and approved services. There is no path out.

5

Private service endpoints

All cloud service communication stays on the provider backbone via private endpoints. None of it touches the public internet.

6

Organizational guardrails

Account-level policies that prevent accidental egress. Opening the boundary requires explicit administrative action and leaves an audit trail.

Public AI vendors

"We won't look."

A policy promise. Enforced by access controls inside a third-party boundary. Revocable at any time without notice.

Totally Private AI

"We can't look."

An architectural constraint. Per-user encryption. No standing access to your environment. The boundary is enforced by infrastructure, not by a policy document.

Encryption

Per-user encryption, not per-tenant

Every user gets a unique encryption key. A compromised key exposes one user's data, not the entire organization's.

Totally Private AI offers two tiers. Pro is a managed SaaS where TPAI operates the infrastructure. Enterprise deploys into your own cloud account with customer-owned keys.

Pro (multi-tenant SaaS)

TPAI-managed keys

Per-user encryption. Every user's chat data is encrypted with a unique key. There is no single master key that decrypts all users at once.

Encrypted at rest. All user data is encrypted at rest using keys managed by TPAI inside the air-gapped boundary.

Same air-gapped boundary. No internet egress, no public endpoints. The boundary that protects your data is the same architecture used in Enterprise.

TPAI cannot read your chats. Key material never leaves the air-gapped environment. There is no internet path for it to travel. TPAI operators can maintain the platform without accessing user data. The encryption architecture is documented in full during the security review.

Enterprise (dedicated)

Customer-owned keys

Your cloud account. The entire environment deploys into an account you own and control.

Your KMS keys. Keys generated in your account. TPAI never has access to key material in production.

Your audit custody. All audit and logging data stays in your account. If you subscribe to Maintenance/Support, TPAI has read-only access to operational logs for monitoring.

Full key lifecycle control. You rotate, revoke, and manage keys through your own processes and your own identity provider.

Both tiers share the same air-gapped architecture and six isolation layers. Enterprise adds customer-owned account, customer-owned encryption keys, and direct audit custody. Pro users get the same boundary protections. The difference is who manages the keys, not whether the boundary exists.

Data path

Every hop stays inside the boundary

Your device Secure connection Air-gapped boundary AI model Pro connects via certificate-authenticated VPN. Enterprise connects via dedicated fiber or private network link. All internal service calls use private endpoints. No hop touches the public internet. The full traffic path is documented in the architecture review under NDA.

No public endpoints

The API and chat interface are only reachable through a secure connection with certificate-based authentication. There is no public URL to discover or attack.

No third-party SaaS in the data path

Prompts go from your application to the AI model over private endpoints. No middleware SaaS, no third-party analytics, no external SIEM. Operational monitoring and logging stay inside the deployment boundary.

Private endpoints for everything

Every cloud service is accessed via private endpoints on the provider backbone. The AI model, encryption service, storage, and monitoring all communicate without touching the public internet. The model provider does not use your prompts or completions for training.

Access controls

Who can access what, and when

Pro (managed SaaS)

TPAI cannot read your chats

Per-user encryption. Your chat data is encrypted with a key unique to you. There is no single master key that can decrypt all users.

Operator access is infrastructure-only. TPAI engineers can maintain the platform (deploy updates, monitor uptime) without accessing user data. Per-user encryption enforces this at the infrastructure level.

No data access for support. If you open a support ticket, we troubleshoot from logs and metrics. We do not access your conversations.

Enterprise (your environment)

Break-glass only. Customer-approved.

Zero standing access. No one at Totally Private AI has persistent access to your production environment.

Break-glass protocol. Emergency access requires a documented request, MFA, your designated contact's approval, and expires automatically after one hour.

Full audit trail. Every action during break-glass access is logged. The audit record is available to you immediately.

Maintenance/Support. If you subscribe to ongoing support, TPAI has read-only access to operational logs for monitoring. Not to user data.

On both tiers, the architecture enforces the access boundary. Per-user encryption means there is no "read all users" button, even for platform operators.

Compliance

Architecture alignment you can evidence

United States

HIPAA, NYDFS 500, SOC 2, NIST 800-53, SEC, FINRA

Request evidence pack →

European Union

GDPR, DORA, NIS2, EU AI Act, ISO 27001

Request evidence pack →

GCC

PDPL (Saudi/UAE), SAMA, NCA ECC, CBUAE, DIFC/ADGM

Request evidence pack →

Asia-Pacific

MAS TRM, APRA CPS 234, PDPA, PDPB, FSA/FISC, PDPO

Request evidence pack →

Certification roadmap

ISO 27001

In progress

SOC 2 Type II

Planned

ISO 27701

Planned

ISO 42001

Planned

Security resources

Documentation your security team actually needs

We publish the artifacts your compliance and security teams will ask for. Architecture diagrams, data-flow documentation, boundary proofs, and pre-filled questionnaire answers.

Architecture diagram and data-flow documentation

Complete network topology, encryption boundaries, key custody chain, and traffic-flow documentation. Annotated for security review.

Request PDF →

Boundary proof checklist

Egress controls, encryption at rest and in transit, key custody, logging configuration, and access control verification steps. Line by line.

Request PDF →

Regulatory alignment summaries

Region-specific mapping of TPAI architecture controls to regulatory requirements. Available for US, EU, GCC, and Asia-Pacific frameworks.

Request PDF →

Shared responsibility matrix

Clear split of what you own vs. what TPAI operates. Infrastructure, encryption, access control, monitoring, and incident response responsibilities.

Request PDF →

Pre-filled security questionnaires

SIG Lite, CAIQ, and common vendor security questionnaire answers pre-filled and ready for your procurement process.

Request PDF →

Penetration test summary

Third-party penetration testing is planned. Results and remediation summary will be available under NDA once complete.

Contact us for timeline →

Need something specific?

If your security review requires documentation not listed here, tell us what you need. We will either share an existing artifact or produce one.

Operational transparency

How we operate

Vulnerability disclosure

Report security vulnerabilities to security@totallyprivate.ai.

We acknowledge reports within 2 business days and provide an initial assessment within 5 business days.

Good-faith security research is welcome. We will not pursue legal action against researchers who report responsibly and do not access other users' data.

Data residency

Pro hosting region: US East (Virginia).

Additional regions are planned. Enterprise deploys in the region of your choice. We do not transfer user content across regional boundaries.

For data processing terms, see our Privacy Policy and Data Processing Addendum.

Data retention (Pro defaults)

Chat data: retained while subscription is active, plus 30 days post-cancellation. Encrypted per-user; key deletion renders data irrecoverable.

Usage metadata: up to 90 days.

VPN and infrastructure logs: up to 30 days.

Audit trail logs: up to 30 days.

Enterprise customers control their own retention policies.

Architecture you can audit. Privacy you can prove.

Start with the evidence pack for your region, or schedule a technical walkthrough with our security team.

Or reach us directly at security@totallyprivate.ai