Where your data goes
| Data | Where it goes |
|---|---|
| Prompts, documents, images, audio and answers | From your users' devices to your server and back. Not stored by the server, not logged, not sent to Software Tailor. |
| Requests to a cloud model | Only if an operator configures a cloud provider and a user picks one of its models; that provider's terms then apply. |
| Usage and audit records | On your server: time, endpoint, model, key, app, status, timing and token counts — never content. |
| Licence activation | Licence key, random installation and machine ids, node name, operating system family — to Software Tailor's licence service, about weekly. |
| Product telemetry | Content-free counts, only with consent and where regional rules allow. |
Full detail, including every outbound connection: security.
Controls available
- API keys per person and application, with expiry, model and endpoint limits, and administration rights kept separate.
- HTTPS with a built-in or your own certificate.
- Rate limits, daily quotas and monthly budgets per key (Commercial).
- Approved, deprecated and blocked models; curated mode so users cannot add models (Commercial).
- Content rules and moderation on requests and answers (Commercial).
- A content-free audit log with signed, offline-verifiable exports and optional delivery to your SIEM (Commercial).
- Region policy for where cloud providers may run and how long audit records are kept.
What we do not claim
- No certifications. AI Server is not certified to SOC 2, ISO 27001 or similar standards, and we do not describe it as "compliant" with a regulation. It gives you controls that help you meet your obligations; your use determines compliance.
- Not a fully disconnected product. Inference works offline, and a server keeps serving through a licence-service outage of up to 7 + 7 days, but licensing needs periodic outbound access.
- Model output is not guaranteed. AI models can be wrong, biased or produce unsuitable content. Keep a person responsible for decisions, and use content rules and moderation where needed.
Shared responsibilities
| Software Tailor | You |
|---|---|
| The software, its security fixes and updates | Installing updates; the operating system, network and hardware |
| Documented, content-free data flows | Who has keys; HTTPS; firewall and network exposure |
| Licence and activation service | Model choice and the licences of the models you use |
| Support for the product | Lawful use, data-protection assessments and records, backups |
Model licences
Open models come with their own licences, some with restrictions on commercial use or usage thresholds. The model catalogue shows each model's licence; check it before you approve a model for business use.
For your reviewers
- Security architecture — authentication, licensing, data inventory, outbound connections.
- Trust centre — company-level data paths and responsibilities.
- Procurement — documents and answers for supplier reviews.
- Hardening checklist — for the team that operates it.