Access & tools
Identity, permitted tools, budgets and agent policies.
TAC / ARCHITECTURE
A policy boundary between your organization and its models. Decide what can leave, where it can go and what gets recorded.
Identity, permitted tools, budgets and agent policies.
Map data classes to approved destinations and actions.
Replace selected identifiers and control their restoration.
Your key. Your contract.
Open models inside a TEE.
No model call. Record the denial.
THE PRIVATE TIER
Use a private route for open models in trusted execution environments. Workload policy determines whether that route is permitted.
Check hardware attestation against your approved environment before sending a sensitive workload.
Link the chosen route to a policy version and an inspectable request receipt.
TEE assurance depends on hardware, software and the attestation chain. It does not eliminate all security risks.
EVIDENCE, WITH A DEFINED SCOPE
Connect each policy decision to its selected execution path. A signature alone does not prove perfect data classification or everything a downstream provider does.
For on-chain anchoring, use commitments to receipt batches. Keep the underlying content inside your boundary.
DEPLOYMENT OPTIONS
Subscription and usage-based gateway service. Model-provider charges remain on your BYOK agreement.
Deploy the gateway within your cloud boundary, with defined key custody, support access and operating responsibilities.
License and support for a customer-operated deployment. Private inference availability depends on suitable infrastructure.
PILOT CHECKLIST
Scope one workload before committing to a wider rollout. Map deployment, integration and access requirements to your team.
Define the application, model access, data classes and permitted destinations.
Document what stays private, who can restore values and who operates each component.
Test classification errors, false positives, latency, denied requests and dependency failures.
Check receipt integrity, audit access, export and recovery before production use.