Security & deployment
Your data stays inside your walls.
Closed-KB zero egress, PII redaction, RBAC, and a sealed audit log — deployed as SaaS, self-hosted, or fully air-gapped. Prove compliance without slowing the business down.
Prove it — without letting anything leave your walls
Evigauge is built to sit inside the trust boundary you already defend. Every request crosses a boundary you define; every crossing is recorded, and whatever your posture forbids is blocked. A live audit trail, not a promise.
- Closed-KB workspaces with a hard no-egress guarantee.
- PII redaction before storage; text capture is opt-in.
- Tenant isolation enforced at write and read.
- Bring your own provider and keys — encrypted, never logged, never echoed.
You set the trust boundary
An open-web toggle, per workspace, decides whether verification may reach past your walls. Turn it off and Evigauge runs closed-KB: the work that can't touch the open web never does, and there is no egress past the IP wall.
Closed-KB mode
Verification stays inside your sanctioned knowledge base — nothing reaches the open web.
No-egress guarantee
With the open-web toggle off, requests never cross your boundary. Blocked crossings are logged.
Query alignment
Every answer is checked against your KB and attributed to the person who ran it.
Drift alerts
Get told when quality trends away from your sanctioned knowledge — daily, not after an incident.
How your data is handled
Least privilege by default. Keys are encrypted and never written to a log; sensitive fields are redacted before storage; access is scoped and recorded.
- Bring your own provider and keys — encrypted at rest, never logged, never echoed.
- PII redaction before storage; raw text capture is opt-in.
- Tenant isolation enforced at write and read.
- RBAC — owner / admin / dev scopes, with an access audit trail.
- Zero-loss ingest posture — spans are never silently dropped; failures surface.
Deploy your way
Run Evigauge where your data-handling rules require — from managed SaaS to a fully air-gapped install. Every reconstruction engine toggles per workspace, with no redeploy.
SaaS
Managed and multi-tenant, isolated at write and read. The fastest path to your first trace.
Self-host
Run it in your own cloud or VPC, under your own controls and network policy.
Air-gapped
A fully closed install for environments that can't reach the public internet at all.
Bring your own provider
Any model provider, any keys. Engines toggle per workspace with no redeploy — no lock-in.
Audit-ready by construction
Because every crossing, redaction, and verdict is recorded as it happens, compliance isn't a report you assemble after the fact — it's the sealed log the system already keeps. Prove what your AI did, to whom, and why, on demand.
- A sealed, append-only audit log of every boundary crossing and access.
- Per-answer provenance and grounding evidence, attributable to a user.
- Control on the record — what was enforced, blocked, or redacted, and when.
See it on your own traffic.
45 minutes, your real traces — provenance, reasoning, and cost, reconstructed.
Deployment options and controls reflect the product plan; specifics are confirmed during your security review.