Verify the boundary before you buy.
This is the current evidence map for Software Tailor's private AI products: what runs where, which controls are implemented, what Software Tailor can receive, and which responsibilities remain with the customer.
Reviewed 22 August 2026
The page describes implemented product behaviour and known limitations. Roadmap work is not presented as a current control.
Controls are evidence, not a compliance certificate
Software can enforce or evidence part of a control environment. It cannot certify the organisation that deploys it, choose a lawful use case, or replace the customer's legal, risk and operational processes.
Product behaviour
Data paths, authentication, revocation, quotas, audit records, monitoring, backup and offline modes can be reviewed against the product and its documented scope.
Deployment responsibility
The customer chooses models, users, network exposure, TLS termination, retention, backup schedules, monitoring alerts, acceptable use and incident procedures.
External certification
Software Tailor does not claim SOC 2 or ISO 27001 certification, an external security attestation, or automatic GDPR or EU AI Act conformity on this page.
Who can receive what?
The answer changes with the route the customer selects. “Private AI” describes a deployment path, not permission to ignore an optional provider or organisation service.
| Route | Prompt and document content | What Software Tailor may receive | Primary operator |
|---|---|---|---|
| Published app + local model | Stays on the user's device. | No prompt, document or generated content. Consent-gated operational telemetry may be enabled; it must exclude content, file names, full paths, emails, IP addresses, secrets and account identifiers. | User or device administrator |
| App or API client + customer AI Server | Travels between the approved client and the customer's server. | No inference content. Licensing or support interactions may involve entitlement and installation metadata. | Customer infrastructure team |
| AI Admin Console and organisation services | The Console does not run inference or process prompts and documents. | Work identity and authorised organisation-management records such as members, entitlements, policy, installation inventory, usage totals and audit metadata. | Customer administrator and Software Tailor service boundary |
| Optional third-party cloud model | Sent to the provider the user deliberately selects under that provider's terms. | Software Tailor does not become the inference provider merely because an app offers the optional route. | Customer and selected provider |
Implemented scope and the limitation beside it
A green product control still needs correct deployment. A product-specific control must not be assumed across every server or app.
| Control area | Current evidence | Boundary or limitation |
|---|---|---|
| Organisation identity | AI Admin Console uses OpenID Connect with Microsoft Entra ID or Google Workspace. The Google path requests only openid, email and profile. | AI Server itself is governed with API keys; it is not a per-user workforce sign-in surface. The customer remains responsible for tenant, domain and member policy. |
| API access and abuse limits | AI Server supports hashed API keys, endpoint or model scope, revocation, per-key rate limits, daily request caps and monthly budget limits. | Keys must be issued per caller and rotated by the operator. Estimated cost is a chargeback aid, not an invoice. |
| Audit evidence | AI Server produces content-free audit records and signed export bundles with a public verification key. AI Admin Console has its own organisation-action audit and CSV export. | A cryptographic signature supports integrity verification; it is not an external audit opinion. Server and Console evidence use different scopes and mechanisms. |
| Monitoring and fleet health | AI Server exposes an authenticated Prometheus endpoint, live connections and usage views. Enrolled servers send content-free health heartbeats to the Console fleet view. | Customers define alerts, retention and escalation. Deeper cross-product aggregation varies by product. |
| Region and provider policy | Server policy can declare a region, restrict optional provider regions and fail closed for configured rules before an optional cloud call. | The customer must select the right policy, validate provider terms and prove that the configuration matches its obligations. |
| Network protection | A non-loopback AI Server refuses to start without both a paid entitlement and an API key. Kubernetes and reverse-proxy deployments are documented. | TLS termination and network segmentation are operator responsibilities. AI Server guidance places TLS at the customer's trusted ingress or reverse proxy. |
| Offline and air-gapped operation | Supported deployments can pre-stage app packages, engines, approved model packs and catalogue metadata, then disable telemetry or use an internal collector. | The full update, licence, recovery and support procedure must be tested inside the customer's disconnected environment. Browser and mobile heads need an internal remote engine. |
| Backup and recovery | AI Server ships a one-file configuration backup, restore and snapshot workflow. | Do not generalise that control: the same guided backup card is not currently shipped across every specialist app server or governance component. |
Trust is a shared operating responsibility
Software Tailor
- Document product defaults, control scope and known limitations.
- Maintain verified acquisition, licensing and update paths for public releases.
- Support reproducible product issues and privately received vulnerability reports.
Customer organisation
- Classify the workload, data, users, models and acceptable decisions.
- Configure identity, keys, ingress, retention, backup, monitoring and incident response.
- Validate legal duties, human oversight and evidence for the deployed use case.
Optional provider
- Receives content only when the customer deliberately selects its route.
- Operates under its own contract, retention, residency and security terms.
- Must be assessed separately from the local or customer-hosted Software Tailor path.
Review before a questionnaire or NDA
Start with the exact product and deployment. These public resources establish the architecture and current acquisition boundary before a sales conversation.
Lifecycle status and verified public acquisition channels. Private AI buyer guide
Deployment layers, data paths, evaluation and current availability. AI Server operations and hardening
Prometheus metrics, usage boundaries, API-key practice and trusted-proxy guidance. AI Admin Console data scope
Identity scopes, organisation records and management responsibilities. Privacy Policy
Company-level collection, service providers, retention, rights and contact details.
Direct answers for security and procurement teams
Is Software Tailor SOC 2 or ISO 27001 certified?
We do not make that certification claim here. We maintain product-control mappings as engineering aids, not attestations. Ask for the current evidence relevant to your deployment rather than relying on an implied badge.
Do prompts or documents reach Software Tailor?
Not through the local-model or customer-hosted AI Server inference paths. An optional cloud-model path sends selected content to that provider. Organisation services can process management metadata, not model prompts or responses.
Is telemetry required?
No. Product telemetry and error reporting are consent-gated and can be disabled. Offline deployments can operate with no outbound telemetry or can use an approved internal collection route where documented.
Can we deploy in an air-gapped environment?
Supported products can be pre-staged with packages, engines, models and metadata. Treat the complete acquisition, signature verification, licence, update, recovery and support process as part of the pilot.
Is everything encrypted automatically?
Do not assume one universal answer. Product pages document local storage behaviour. For networked AI Server deployments, the customer configures TLS at a trusted ingress or reverse proxy and controls storage, backup and key handling.
Will you complete our security questionnaire?
Contact us with the product, deployment path, workload and deadline. We will separate public evidence, customer-controlled configuration and any information that requires a private review.
Send suspected vulnerabilities privately
Email [email protected] with the affected product and version, impact, reproduction steps and a safe proof of concept. Do not include live customer data or publish exploitable details before we have reviewed the report.
Review one real workload, not an abstract platform
Bring the data classification, users, network boundary, model choice, retention rule and recovery requirement. We can map the implemented controls and open gaps before the pilot begins.