Security

Security, governance and audit for on-prem AI

Data isolation inside your own perimeter, access enforced at the data layer, source-grounded answers and an audit-ready log of every question. Built for regulated and high-trust environments.

Deployment models

On-prem first. Dedicated single-tenant private cloud when it fits the path.

CortexMine deploys in two models: on-prem on dedicated hardware inside your data center, or in a dedicated single-tenant private cloud. On-prem is our default. In both models the environment is yours alone: dedicated compute, isolated network, data never leaves your perimeter.

On-prem

Default
  • Dedicated appliance in your server room or data center.
  • Full physical control over hardware and data. Air-gapped configurations available.
  • For organizations with their own server infrastructure and strict data residency requirements.

Dedicated single-tenant private cloud

Single-tenant
  • The same platform on dedicated single-tenant infrastructure, reserved exclusively for your organization.
  • No shared compute, no shared models, no multi-tenancy. An isolated environment under your governance.
  • For organizations without their own server room, or teams that want to start faster and move on-prem later.

Both models run the same tiers and the same flat monthly fee. Tiers, not tokens. Pricing is shared after scoping.

Security & governance

Built for regulated environments.

Architecture facts, not marketing. No claimed certifications we don't hold.

Data never leaves your perimeter

On-prem on dedicated hardware, or a dedicated single-tenant private cloud under your governance.

Source-grounded answers

Every answer cites the documents it came from.

Audit-ready log

Every question and answer is recorded and traceable.

Role-based access control

Access follows your roles and permissions.

Human-in-the-loop

AI proposes, your people approve. High-stakes decisions stay human.

Operated for you

Deployment, updates and hardware refresh handled by CortexMine. No internal AI team required.

ACCESS CONTROL

The AI only sees what each person is allowed to see.

Permissions are not a filter placed on a finished answer. A person's role and group decide which documents can enter the answer at all. The same prompt from two people returns results from different sources when their access differs. Control is enforced on every request, at the data layer.

  • Access granted by role and by group
  • Enforced at the data layer, not the UI
  • Full isolation between teams and projects
WHY REGULATED BUYERS TRUST IT

Built for audit, not bolted on later.

Every part of an answer leaves a trace you can show an auditor.

Audit-ready record of every answer

The question, the sources used, the document version and timestamps saved as a durable record.

Off-topic content is dropped

Passages unrelated to the question are dropped before the answer is written.

Evidence self-check

The assistant checks whether it has enough sources and pulls more instead of guessing.

Citation freshness

A citation shows the document version from the moment the answer was given, not today's state.

GDPR-grade deletion

A document is removed from every layer of the system and citations to it are marked as removed.

Human in the loop

The AI proposes, your people review and sign off.

The regulatory clock

  1. October 3, 2026

    Key entities enter the register

  2. April 3, 2027

    Polish transition period ends, Article 21 measures required

  3. April 3, 2028

    First audits of key entities

Internal security policy points the same way.

Why this is possible now

  • Open-weight models crossed the quality threshold in 2025.
  • Inference that needed a data centre runs on one appliance.
  • A private deployment goes live in weeks.