Security architecture
No internet egress. Per-user encryption. No standing access to your data.
Every security claim on this page is an architectural constraint, not a policy promise. Your security team can verify each one independently.
Six isolation layers. No outbound route. Encrypted per user.
Security principles
These are structural properties of the environment, not policy toggles. Changing any of them requires rebuilding the infrastructure. Any exception requires explicit change control and leaves an audit trail.
No internet gateway. No NAT gateway. No public IP addresses. No route to 0.0.0.0/0. Traffic cannot leave the boundary because there is no path out. Verified by route table inspection, not by reading a policy document.
Every user's chat data is encrypted with a unique key. In the SaaS environment, there is no single master key that can decrypt all users. In Enterprise, your organization owns the key hierarchy and your admins control access to every user's keys through your own processes. The encryption architecture is documented in full during the security review.
On Enterprise, no one at TPAI has persistent access to your production environment. Emergency access requires a documented request, MFA, your approval, and expires after one hour with a full audit trail. On Pro, TPAI operators maintain the infrastructure but do not access your encrypted chat data.
Defense in depth
The environment is protected by six layers of network and access controls, spanning network architecture, traffic rules, routing, private service endpoints, and organizational guardrails. The full architecture walkthrough is available under NDA as part of our security review.
1
Private subnets only. No internet gateway. No NAT gateway. No public IP addresses anywhere in the environment.
2
Deny-all defaults at the subnet level. Only explicitly allowed traffic between internal services passes through.
3
Per-resource firewall rules with tightly scoped ingress and egress. No default "allow all" posture anywhere in the stack.
4
No default route to the public internet. Traffic can only reach internal endpoints and approved services. There is no path out.
5
All cloud service communication stays on the provider backbone via private endpoints. None of it touches the public internet.
6
Account-level policies that prevent accidental egress. Opening the boundary requires explicit administrative action and leaves an audit trail.
Public AI vendors
"We won't look."
A policy promise. Enforced by access controls inside a third-party boundary. Revocable at any time without notice.
Totally Private AI
"We can't look."
An architectural constraint. Per-user encryption. No standing access to your environment. The boundary is enforced by infrastructure, not by a policy document.
Encryption
Every user gets a unique encryption key. A compromised key exposes one user's data, not the entire organization's.
Totally Private AI offers two tiers. Pro is a managed SaaS where TPAI operates the infrastructure. Enterprise deploys into your own cloud account with customer-owned keys.
Pro (multi-tenant SaaS)
Per-user encryption. Every user's chat data is encrypted with a unique key. There is no single master key that decrypts all users at once.
Encrypted at rest. All user data is encrypted at rest using keys managed by TPAI inside the air-gapped boundary.
Same air-gapped boundary. No internet egress, no public endpoints. The boundary that protects your data is the same architecture used in Enterprise.
TPAI cannot read your chats. Key material never leaves the air-gapped environment. There is no internet path for it to travel. TPAI operators can maintain the platform without accessing user data. The encryption architecture is documented in full during the security review.
Enterprise (dedicated)
Your cloud account. The entire environment deploys into an account you own and control.
Your KMS keys. Keys generated in your account. TPAI never has access to key material in production.
Your audit custody. All audit and logging data stays in your account. If you subscribe to Maintenance/Support, TPAI has read-only access to operational logs for monitoring.
Full key lifecycle control. You rotate, revoke, and manage keys through your own processes and your own identity provider.
Both tiers share the same air-gapped architecture and six isolation layers. Enterprise adds customer-owned account, customer-owned encryption keys, and direct audit custody. Pro users get the same boundary protections. The difference is who manages the keys, not whether the boundary exists.
Data path
The API and chat interface are only reachable through a secure connection with certificate-based authentication. There is no public URL to discover or attack.
Prompts go from your application to the AI model over private endpoints. No middleware SaaS, no third-party analytics, no external SIEM. Operational monitoring and logging stay inside the deployment boundary.
Every cloud service is accessed via private endpoints on the provider backbone. The AI model, encryption service, storage, and monitoring all communicate without touching the public internet. The model provider does not use your prompts or completions for training.
Access controls
Pro (managed SaaS)
Per-user encryption. Your chat data is encrypted with a key unique to you. There is no single master key that can decrypt all users.
Operator access is infrastructure-only. TPAI engineers can maintain the platform (deploy updates, monitor uptime) without accessing user data. Per-user encryption enforces this at the infrastructure level.
No data access for support. If you open a support ticket, we troubleshoot from logs and metrics. We do not access your conversations.
Enterprise (your environment)
Zero standing access. No one at Totally Private AI has persistent access to your production environment.
Break-glass protocol. Emergency access requires a documented request, MFA, your designated contact's approval, and expires automatically after one hour.
Full audit trail. Every action during break-glass access is logged. The audit record is available to you immediately.
Maintenance/Support. If you subscribe to ongoing support, TPAI has read-only access to operational logs for monitoring. Not to user data.
On both tiers, the architecture enforces the access boundary. Per-user encryption means there is no "read all users" button, even for platform operators.
Compliance
ISO 27001
In progress
SOC 2 Type II
Planned
ISO 27701
Planned
ISO 42001
Planned
Security resources
We publish the artifacts your compliance and security teams will ask for. Architecture diagrams, data-flow documentation, boundary proofs, and pre-filled questionnaire answers.
Complete network topology, encryption boundaries, key custody chain, and traffic-flow documentation. Annotated for security review.
Request PDF →Egress controls, encryption at rest and in transit, key custody, logging configuration, and access control verification steps. Line by line.
Request PDF →Region-specific mapping of TPAI architecture controls to regulatory requirements. Available for US, EU, GCC, and Asia-Pacific frameworks.
Request PDF →Clear split of what you own vs. what TPAI operates. Infrastructure, encryption, access control, monitoring, and incident response responsibilities.
Request PDF →SIG Lite, CAIQ, and common vendor security questionnaire answers pre-filled and ready for your procurement process.
Request PDF →Third-party penetration testing is planned. Results and remediation summary will be available under NDA once complete.
Contact us for timeline →If your security review requires documentation not listed here, tell us what you need. We will either share an existing artifact or produce one.
Operational transparency
Report security vulnerabilities to security@totallyprivate.ai.
We acknowledge reports within 2 business days and provide an initial assessment within 5 business days.
Good-faith security research is welcome. We will not pursue legal action against researchers who report responsibly and do not access other users' data.
Pro hosting region: US East (Virginia).
Additional regions are planned. Enterprise deploys in the region of your choice. We do not transfer user content across regional boundaries.
For data processing terms, see our Privacy Policy and Data Processing Addendum.
Chat data: retained while subscription is active, plus 30 days post-cancellation. Encrypted per-user; key deletion renders data irrecoverable.
Usage metadata: up to 90 days.
VPN and infrastructure logs: up to 30 days.
Audit trail logs: up to 30 days.
Enterprise customers control their own retention policies.
Start with the evidence pack for your region, or schedule a technical walkthrough with our security team.
Or reach us directly at security@totallyprivate.ai