Security &
Compliance
Compliance Ready
Built for Organisations that cannot afford to Guess
How to read this page
Every claim here is something the platform does
Built for organisations that cannot afford to guess. Every claim on this page is something the platform does, with the mechanism named beside it. A certification held by the infrastructure underneath is that provider’s to state, and is not claimed here.
Compliance ready
Built for organisations that cannot afford to guess
Six of the seven headings below are things the engine enforces at the moment of the write or the read, not policies written down and hoped for. The seventh is the list you take to your board.
Your security team will ask where the data goes, what left for the model, who could see which column, and what you can prove afterwards. Each of those has an answer with a route or a record behind it, and they are in order below.
One
Your model. Your key. Your control.
Data Oil holds no AI model of its own. Your organisation’s AI endpoint and your own API key are registered per customer, assigned per database, sealed on the way in and never returned by any route. You are not sharing model access with another organisation, and the engine loads no model of its own to answer a question.
AI servers you allocate. Your administrator attaches the servers that do translation, embedding, transcription and the assistant, through the UI or the API — nothing issues or rotates a credential by itself. Each server’s credential is sealed on the way in and shown afterwards only by its fingerprint. Work is spread across the servers and moves on when one stops answering.
Two
What leaves your environment — documented
Every question can be prepared without being sent. POST /query/prepare returns the whole submission — the system prompt, the evidence selected, the citations and the byte count — and sends nothing. What is actually sent is retained and auditable. Byte for byte. Question by question.
That is the difference between a policy about data leaving and a record of what left. Your board asks the second question.
Three
Where your data lives — your choice
Residency is enforced at the database level, as an architecture constraint rather than a policy. A write to a database placed outside its declared region is refused, and nothing is stored. You choose where; it stays there.
Oracle Cloud, AWS, Azure, Google Cloud or your own object storage, several at once across one estate, with the placement decided per database.
Four
Access control down to a single column
Sensitive fields can be fenced — visible to some users, invisible to others — without building a separate system to manage it. A column marked read-only is read-only for everybody, on both query surfaces, and a narrowed read is written to the audit so the narrowing itself is evidence.
Sign-on is your own directory. A directory group reaches a role as directory:<group>, and every permission decision reads it beside the engine’s own groups.
Every door asks the same questions. A permission set in the UI — a database right, a role’s column grant, a classification, a database closed for maintenance, an address allowlist, a disabled account — holds over the API, the PostgreSQL port, the live change feed and the AI assistant alike. The assistant answers as the person asking, so it never quotes a field they could not query themselves.
Five
The audit log — every act, not a sample
Every read, write, query and AI interaction is recorded. Not sampled — every act. A page opened, a control pressed, a sign-in: every act on the console lands in your own audit, and nothing on the customer surface can remove a line. Your compliance team can pull the full history, and export it as xlsx or csv.
Backups are proved the same way: every chain is verified by a real restore drill on the cadence you choose, you restore your own copy from the console, and the console shows proved with the date it was proved on.
Six
Twelve regulatory regimes
Declared per job and per column, and the platform acts on the declaration rather than filing it.
- Australia IRAP
- CSA STAR
- FedRAMP
- GDPR
- HIPAA
- ISO/IEC 27001
- PCI DSS
- Singapore MTCS
- Spain ENS
- SOC 1
- SOC 2
- SOC 3
These twelve are what the platform itself declares and enforces. A certification held by the cloud provider underneath is that provider’s to state, and we do not claim it as ours.
Seven
Six things you can say to your board, with the proof beside each
What you can say
“Our AI uses our model and our key, not the vendor’s.”
The engine loads no model of its own
Endpoints are registered per customer and assigned per database, with a key that is sealed on the way in and never returned by any route.
What you can say
“We know what leaves our environment, documented.”
Prepared without being sent
POST /query/prepare returns the whole submission — system prompt, evidence, citations and byte count — and sends nothing. What is sent is retained and auditable.
What you can say
“Our data stays where we say it stays.”
Refused, not logged
A write to a database placed outside its declared region is refused and nothing is stored. Residency is enforced rather than recorded.
What you can say
“Access is controlled at the column level.”
One fence on every door
A column marked read-only is read-only for everybody, on both query surfaces, and a narrowed read is written to the audit.
What you can say
“Every action is in the audit log.”
Every act, not a sample
Every read, write, query and AI interaction is recorded, and nothing on the customer surface can remove a line. Exportable as xlsx or csv.
What you can say
“We can show finance exactly what we spent and why.”
The invoice reconciles to the meter
Every charge is a dated record kept 400 days, and the month’s records add up to the figure on the usage page — traceable to the team and the service that incurred it.
Ask us the hard one
Send us the question your security team will ask.
If the answer is a route, a record or a refusal, we will name it. If it is a roadmap item, we will say that instead.
Your security team’s question, answered with the mechanism
Tell us what you have to satisfy, where the data has to stay, and the date you need an answer by.
Contact us Your concerns, one by one