Skip to content

Security & Data Protection at ARBA

How we design, deploy and operate AI systems without taking data out of your control — the architectural approach behind our platforms and projects.

AI where your data already lives

Your infrastructure

Systems run inside your own perimeter — servers you control, networks you manage.

Your cloud

Deployment into your own cloud subscription; models and keys stay in your tenancy.

On-premises

Full on-prem installation for regulated environments, updated without inbound access.

Air-gapped

Air-gap is a first-class mode for Nexus: pull-only releases, no callbacks, offline licensing.

Egress under control

In sovereign deployments the control plane holds no customer data; the only egress is a data-free licence heartbeat.

A runtime egress latch refuses to boot unless inference is pinned to an approved endpoint, and hard-blocks any call outside the perimeter.

The AI never outruns the person

SSO & corporate directory

Sign-in through your identity provider; accounts and roles follow your directory.

On-behalf-of execution

AI can never exceed the rights of the person who launched it; authorization is re-checked per request.

Role-based permissions

Access is scoped by role and area; administrative actions are separated from everyday use.

Every step accountable

Append-only trace

Every reasoning step and action lands in an append-only, replayable trace.

Per-read access logging

Document access is logged per read, not per session.

Human-gated write-back

Changes to systems of record require explicit human confirmation.

Your models, your keys

Bring your own model: OpenAI-family and Anthropic Claude lanes proven inside a customer's own cloud — keys never leave your perimeter.

Encryption extends to the derived AI plane: abstracts, digests and claims are encrypted, not just the source data.

What we do not claim

  • We do not currently claim ISO or SOC certification; our security posture is demonstrated architecturally and per engagement
  • Specific capabilities depend on the deployment mode — cloud, on-prem and air-gap profiles differ
  • A security review with your team is part of every engagement before production

Data processing questions

Questions about security architecture or data processing: [email protected].

Bring your security team — we speak their language

Security & Data Protection at ARBA