Security & Compliance

Security is the product, not a feature.

We build for banks, hospitals, universities, enterprises, and governments, institutions where a single mishandled record is a regulatory event, not an inconvenience. So we don't bolt security on at the end. It is the constraint we design inside from the first line.

Data sovereignty

Your documents, embeddings, and queries stay on infrastructure you own: on-premise, air-gapped, or hybrid. Data never crosses your perimeter to reach us, because the system runs where the data already lives. When your regulator asks where information is processed, the answer is a rack you control, with logs to prove it.

Access control

Role-based access control maps to your existing identity provider via SSO. Permissions extend down to row- and column-level on your data, so an answer only ever draws from sources the asking user is already entitled to see. No privilege escalation through the assistant.

Auditability

Every query, retrieval, and answer is written to a tamper-evident, append-only log. Each answer carries the citations it was built from, down to the document version, so months later you can reconstruct not just what the system said, but exactly which source it relied on.

Deployment models

Air-gapped

No outbound route. The model, your data, and every query stay on isolated hardware. The standard for classified and core-banking environments.

On-premise

Runs in your own data center, behind your firewall, integrated with approved internal services. You own the hardware and the audit trail.

Hybrid

Sensitive data and inference stay inside your perimeter; only non-sensitive orchestration touches the outside, and you define exactly what that is.

Compliance

We align our controls to the frameworks our customers are held to. Status is tracked transparently: we'd rather tell you what's certified and what's on the roadmap than imply a badge we don't yet hold.

SOC 2 Type II

Controls for security, availability, and confidentiality, audited over time.

[in progress / on roadmap: confirm status]
ISO 27001

Information security management system covering risk, controls, and continuous review.

[in progress / on roadmap: confirm status]
GDPR

Lawful processing, data-subject rights, and residency for EU personal data.

[in progress / on roadmap: confirm status]
HIPAA

Safeguards for protected health information in clinical deployments.

[in progress / on roadmap: confirm status]
DPDP Act

India's Digital Personal Data Protection framework for consent and processing.

[in progress / on roadmap: confirm status]
Responsible disclosure

Found something? Tell us.

We welcome reports from security researchers. If you believe you've found a vulnerability in our website or products, email teclops.ai@gmail.com with the details and steps to reproduce. Please give us reasonable time to investigate and remediate before any public disclosure, and avoid accessing or modifying data that isn't yours. We will acknowledge your report and keep you updated on our progress.

Bring your security team. We'll answer their questions.

Contact Us