TAC / ARCHITECTURE

Control the route.
Keep the evidence.

A policy boundary between your organization and its models. Decide what can leave, where it can go and what gets recorded.

Employees · Applications · AI agents
TAC GATEWAY / YOUR POLICY BOUNDARY
01

Access & tools

Identity, permitted tools, budgets and agent policies.

02

Classify & route

Map data classes to approved destinations and actions.

03

Privacy vault

Replace selected identifiers and control their restoration.

Request receiptPolicy version · class · route · decision · signatures
GENERAL / TOKENIZED

Frontier model

Your key. Your contract.

CONFIDENTIAL

Private tier

Open models inside a TEE.

RESTRICTED

Block

No model call. Record the denial.

THE PRIVATE TIER

Confidential work.
Constrained execution.

Use a private route for open models in trusted execution environments. Workload policy determines whether that route is permitted.

EXECUTION

Inspect the environment.

Check hardware attestation against your approved environment before sending a sensitive workload.

ACCOUNTABILITY

Record the decision.

Link the chosen route to a policy version and an inspectable request receipt.

TRUST BOUNDARIES

Make assumptions explicit.

TEE assurance depends on hardware, software and the attestation chain. It does not eliminate all security risks.

EVIDENCE, WITH A DEFINED SCOPE

A receipt should
say what it proves.

Connect each policy decision to its selected execution path. A signature alone does not prove perfect data classification or everything a downstream provider does.

Inside the receipt

  • Request reference and timestamp
  • Policy version and assigned data class
  • Allowed route or denial decision
  • Execution attestation reference, where available
  • Signatures and batch anchor reference

Inside your boundary

  • Raw prompts and sensitive source values
  • Vault mappings and restoration permissions
  • Customer-controlled encrypted audit records

For on-chain anchoring, use commitments to receipt batches. Keep the underlying content inside your boundary.

DEPLOYMENT OPTIONS

Fit your operating boundary.

01 / MANAGED

Hosted gateway

Subscription and usage-based gateway service. Model-provider charges remain on your BYOK agreement.

02 / CUSTOMER CLOUD

Your VPC

Deploy the gateway within your cloud boundary, with defined key custody, support access and operating responsibilities.

03 / PRIVATE INFRASTRUCTURE

On-premises

License and support for a customer-operated deployment. Private inference availability depends on suitable infrastructure.

PILOT CHECKLIST

Start small.
Make it measurable.

Scope one workload before committing to a wider rollout. Map deployment, integration and access requirements to your team.

  1. 01

    Choose one real workflow.

    Define the application, model access, data classes and permitted destinations.

  2. 02

    Agree on the boundary.

    Document what stays private, who can restore values and who operates each component.

  3. 03

    Measure behavior under pressure.

    Test classification errors, false positives, latency, denied requests and dependency failures.

  4. 04

    Inspect the evidence.

    Check receipt integrity, audit access, export and recovery before production use.