Security you can examine, test, and operate.

Sotaire runs in a dedicated customer environment. Network paths, identity, retention, evidence, backup, and review controls are configured to that environment and verified during handoff.

01
Security review map

The questions a real review should answer.

Security is more than a row of framework badges. These are the operating areas Sotaire documents with the customer.

01

Deployment isolation

Where does the workload run?

On dedicated infrastructure in the customer-controlled environment, sized and segmented for the deployment.

02

Data flow + residency

Where do source data and model traffic go?

Sources, storage, retrieval, and inference paths are documented in the deployment data-flow record.

03

Identity + authorization

Who can access which data and tools?

Users and agents receive scoped roles aligned to the customer’s identity and workspace model.

04

Egress + integrations

What can cross the network boundary?

Approved destinations and brokered calls are explicitly configured, logged, and tested during handoff.

05

Audit evidence

Can an operator reconstruct an event?

Prompts, retrieval context, tool calls, approvals, and configuration activity are retained as reviewable records.

06

Backup + recovery

How is service restored safely?

Backup scope, encryption, retention, restore tests, and recovery ownership are defined per environment.

07

Updates + operations

How does software change after handoff?

Versions, maintenance windows, rollback steps, monitoring, and operator runbooks are agreed with the customer.

08

AI workflow controls

What keeps automation within scope?

Tool allowlists, step limits, citations, checkpoints, and human review are configured to the workflow’s impact.

02
Data flow

A request has a visible path.

The exact services vary by deployment, but identity, retrieval, inference, and evidence stay explicit.

01

Authorized user

Identity and role establish the workspace and sources the request may reach.

02

Scoped retrieval

Approved local collections return passages and provenance for the request.

03

Private inference

The configured model generates within the customer deployment boundary.

04

Review + evidence

Citations, approvals, tool activity, and final output remain available for review.

03
Responsibility

A secure system still needs clear owners.

The handoff names who makes policy decisions, who operates the platform, and what must be validated together.

Sotaire

Platform configuration, deployment baseline, workflow controls, documentation, and implementation support.

Customer

Identity lifecycle, source-data quality, policy decisions, reviewer assignment, facility security, and user governance.

Shared

Architecture approval, integration allowlists, acceptance testing, incident exercises, backup validation, and change review.

Framework posture

Mapped to requirements, never reduced to a badge.

Sotaire can be configured to support a customer’s control environment. Scope, evidence, and responsibility are documented; certification remains with the relevant organization and auditor.

SOC 2 control mapping
ISO 27001 alignment
HIPAA safeguards
GDPR principles
CJIS requirements
PCI DSS scope
Security FAQ

Answers for the first security review.

A few common questions teams ask before private AI enters a controlled environment.

Sotaire runs in a dedicated customer environment. Outbound routes and approved integrations are explicitly configured, brokered where required, logged, and tested during deployment.

Bring your security team to the first call.

We’ll walk through the data flow, identity model, approved network paths, evidence, recovery, and responsibilities for your environment.

Start with a 30-minute scope

Bring the workflow, the sensitive sources, and the review rules. We'll map the deployment boundary and next step.