No cloud AI · No multi-tenancy · Brokered egress only

Security you can verify, not just trust.

Sotaire runs on single-tenant hardware inside your network. Direct outbound paths are blocked by default, and approved cross-boundary calls are brokered, logged, and reconstructable for auditors.

Security pillars

Containment by architecture.

Controlled data egress

Network-level controls block direct outbound paths. Approved cross-boundary calls are explicit, brokered, and audited.

Single-tenant hardware

Your AI runs on dedicated servers we install in your office. No shared cloud, no multi-tenant blast radius, no neighbor risk.

Immutable audit trail

Every prompt, tool call, and approval is logged append-only. Reconstruct any decision, anytime, for any internal or external auditor.

Human-in-the-loop gates

Agents pause for an explicit yes-or-no before anything consequential. Nothing irreversible happens unsupervised.

Data residency by default

All inference, indexing, and storage stay inside your perimeter. Residency isn't a setting to enable — it's the only way it runs.

Scoped access & roles

Role-based permissions map to your directory, so each user and agent sees only what their role allows.

Defense in depth

Concentric controls, from network to record.

L1
Network perimeter

Deployed in an isolated segment with egress filtering. Outbound destinations are denied by default — the model can't phone home because there's nowhere to call.

L2
Tenant isolation

Dedicated hardware per organization. No workload, weights, or cache is ever shared with another customer because there is no other customer on the box.

L3
Identity & access

Authentication against your existing directory, role-based authorization on every request, and per-agent scopes that bound what each one can touch.

L4
Audit & approval

Append-only logging of prompts, retrieved context, actions, and human approvals — the evidence layer that makes boundary controls and oversight reviewable.

0
Direct outbound paths from the secure zone
100%
Single-tenant, on your hardware
24/7
Append-only audit logging
Every
Consequential action gated to a human
Compliance posture

Configured to your frameworks.

Because the platform lives entirely in your environment, your existing controls and certifications extend to it. We configure retention, access, and audit to the frameworks you already answer to.

SOC 2ISO 27001HIPAAGDPRFedRAMP-alignedCJISPCI DSS

Framework alignment is scoped per deployment. Listed standards indicate where Sotaire's controls map; they are not a claim of independent certification on your behalf.

Bring your security team to the first call.

We'll walk through the architecture, the egress controls, and the audit model — and how they map to your requirements.