Skip to content

Platform · Security and AI model governance

Your data in its own instance. No third-party AI service sees it.

Each customer runs in a single-tenant instance that we host. The platform is designed to run with a local AI model, in your environment or ours. Every deployment comes with a model governance statement your model risk function and your examiner can read.

The problem it removes

AI in a compliance program is a model risk question

  • Most AI tools send your customer records to a third-party model you can't inspect, and your vendor review has to account for it.
  • Your model risk function is asked to approve a model that no one can document, because it changes without notice.
  • Shared, multi-customer software means your data sits beside someone else's, and access rules are the only thing between them.

What you see

A governance file for your deployment

Each deployment has a model card, a controls matrix and an EU AI Act crosswalk, gathered in one model governance statement. It names the model, what it's allowed to do, and the controls around it.

Model governance statement · deployment summarySample data
ItemEntry
TenancySingle-tenant instance, container, hosted by Rupture Labs
Language modelOpen-weight model, run locally on our hardware; no fine-tuning
Model roleDrafts text only. Makes no determination.
Data to third-party AI servicesNone
Access rolesDefined roles; monitoring read-only role cannot change records
AttachedModel card · Controls matrix · EU AI Act crosswalk

Illustrative example with invented entries. The statement for your deployment is written for it and signed.

How it works

Rules decide, the model writes, a person signs

  1. Isolate. Your data lives in its own instance, packaged as a container and hosted by us. A request for another customer's record returns "not found", never "forbidden", so the system doesn't even confirm it exists.
  2. Control access. Users hold defined roles. In transaction monitoring, a read-only role can never change anything.
  3. Decide by rule. Every determination is made by written rules. The language model only writes: summaries, narratives, first drafts. It's a standard open-weight model run locally, not a proprietary fine-tuned one, so it can be documented and reviewed like any other model.
  4. Review and sign. A practitioner reviews the output and signs it. The governance statement records how each of these steps is controlled.

Guardrails

What it will never do

  • We don't train a proprietary model on your data. The model is standard and documented, which is the point.
  • It doesn't mix your records with another customer's. Each customer runs on its own instance.

Where it shows up

The work this part does for you

Plain English

What this is, and how anyone does it

Reference articles from our library, cited to the published rules and standards. No sales copy.

Connected parts

What it works with

See the whole platform

Talk to a practitioner

Book a 15-minute chat with our founder.

A real conversation with a senior compliance leader, to see if there's a fit. Not a sales call, not a demo, no pressure.