Enterprise AI security: answers for your security team

This page is written for CISOs and security architects: where data is stored, what crosses your perimeter, who holds the keys, what an AI agent can and cannot do, how we handle incidents — and how to verify all of it before you sign.

  • DeploymentCloud in-region · private · on-prem · air-gapped
  • Training on your dataNever
  • IdentitySSO via SAML / OIDC
  • AuditEvery query and action · SIEM export
Data

Where the data is and who sees it

The six questions every security review starts with, answered directly.

Where data is stored

In the deployment option you choose: BlackGust Cloud in-region, your private cloud, your own servers, or an air-gapped environment. Personal data stays in the jurisdiction its law requires.

Is data used to train models?

No. Cloud models are accessed through enterprise APIs whose terms exclude training on customer data. Local models run entirely inside your infrastructure. Fine-tuning on your corpus happens only in your environment and only when you ask for it.

What goes to external models

Only the fragments needed to answer. Personal data is masked before it leaves. In air-gapped deployments, external calls are disabled completely.

Who at BlackGust has access

Only the named engineers on the project, as agreed with you and for the duration of the work. All access is logged and revoked at handover.

Encryption

Data is encrypted in transit and at rest. In private-cloud, on-premises and air-gapped deployments, your organization holds the keys.

Data deletion

At the end of the contract, data is deleted within the agreed period and a deletion certificate is issued.

Data flows

What crosses your perimeter, in each deployment mode

Four options, four trust boundaries. The dashed line is your perimeter. Read each diagram as an answer to three questions: what leaves, what is masked, and where the keys live.

Mode 01

BlackGust Cloud, in-region

Fastest start. The platform runs in our cloud in the region you choose.

Your perimeterBlackGust Cloudyour regionYour users · SSOYour systemsBlackGust platformLocal modelsFrontier model APImasked fragmentsKeys
Leaves the perimeter
Data read by connectors to the platform in your region; masked fragments to the frontier model API.
Masking
Personal data masked before any model call.
Keys
Managed by BlackGust in the same region.
Mode 02

Your private cloud

The platform runs in your cloud tenant, under your network and identity policies.

Your perimeterYour users · SSOYour systemsBlackGust platformLocal modelsFrontier model APIoptional · maskedKeys
Leaves the perimeter
Only masked fragments, and only if you enable frontier models.
Masking
Masking at the gateway inside your tenant.
Keys
Your cloud key management service.
Mode 03

On-premises

The platform and local models run on your servers in your data center.

Your perimeterYour users · SSOYour systemsBlackGust platformLocal modelsFrontier model APIoptional · maskedKeys
Leaves the perimeter
Nothing by default. Masked fragments through your proxy if you allow frontier models.
Masking
Masking at the gateway, before your proxy.
Keys
Your key management or HSM.
Mode 04

Air-gapped

An isolated network with no internet route. Local models only.

Your perimeterYour users · SSOYour systemsBlackGust platformLocal modelsFrontier model APIno egressKeys
Leaves the perimeter
Nothing. Outbound traffic is blocked at the network level.
Masking
Applied inside for role-based views; no external calls exist.
Keys
Your key management or HSM, inside the enclave.
Controls by deployment

Security controls by deployment option

The same platform, the same controls — what changes is who operates the infrastructure and where the boundary sits. Use this table to pick the mode that fits your risk appetite.

Meters show relative degree (more segments = more). Exact responsibilities are fixed in the contract and the shared-responsibility annex.
ControlBlackGust CloudPrivate cloudOn-premisesAir-gapped
Data
Data residencyYour chosen regionYour tenantYour data centerYour isolated network
Encryption in transit and at rest✓✓✓✓
Who holds the keysBlackGust, in-regionYouYouYou
Masking before external model calls✓✓✓No external calls
Isolation from the internet
Identity and access
SSO via SAML / OIDC✓✓✓✓
Roles from your directory, row- and field-level access✓✓✓✓
Network policy under your control—✓✓✓
Models
Frontier models (OpenAI, Anthropic) via enterprise APIs✓OptionalOptional—
Local open-weight modelsOptional✓✓✓
Operations
Full audit log, exportable to your SIEM✓✓✓✓
Who operates the infrastructureBlackGustYou, with our engineersYou, with our engineersYou, our engineers on site
Speed to first deployment
Threat model

How AI systems get attacked, and how we defend

AI agents add new attack surface to familiar systems. This is a summary of the threat model we share in full with your team, with the controls mapped to each threat.

T1

Prompt injection

AttackInstructions hidden in a user message, an email, a web page or an uploaded document try to override the agent's rules.

Mitigations
  • Instructions and retrieved content are kept separate; content is treated as data
  • Input filtering for override attempts and cross-user data requests
  • Agents can't widen their own rights, so a hijacked prompt hits the same walls
T2

Data exfiltration

AttackAn attacker tries to pull data out through answers, links, tool calls or the model provider.

Mitigations
  • Answers limited to data the user may already see
  • Outbound actions — email, file sharing, external links — need approval
  • Masking before external calls; none at all in air-gapped mode
T3

Privilege escalation

AttackAn agent or user tries to perform actions beyond their role, or chains tools to reach a system of record.

Mitigations
  • Agents act with the rights of the person they serve — never more
  • Least-privilege service accounts per connector, read-only by default
  • Write and payment actions gated by threshold rules and human sign-off
T4

Model supply chain

AttackTampered model weights, poisoned fine-tuning data or a compromised software dependency.

Mitigations
  • Models from vetted sources, verified by checksum and signature
  • Dependencies pinned and scanned; releases signed
  • Reference tests run before every agent update; a quality drop blocks release
T5

Hallucinated output

AttackA confident but wrong answer leads to a bad business decision or an incorrect document.

Mitigations
  • Answers grounded in your sources, with quote and link
  • No source, no answer
  • Human review for any output that leaves the organization
T6

Insider and vendor access

AttackSomeone at the vendor, or an over-privileged administrator, reads data they shouldn't.

Mitigations
  • Named, time-bound access for BlackGust engineers, revoked at handover
  • Every administrative action logged and exportable
  • In on-prem and air-gapped modes, access only under your rules
Agents

An agent never gets more rights than the person it acts for. Every limit is set in configuration and enforced by the platform, not by the model.

Agents

What an AI agent can and cannot do

Can

  • Read data within the user's permissions
  • Draft documents, letters and reports
  • Create tasks and reminders
  • Perform pre-approved actions

Cannot without human approval

  • Change or delete data in systems of record
  • Send documents outside the organization
  • Execute payments or legally binding actions
  • Expand its own permissions
Policy decisionsExample · illustrative data
TimeAgentRequested actionDecision
09:14:02Finance assistantRead Q3 ledger, branch NorthAllowed
09:14:09Finance assistantRead payroll, all branchesDenied · role
09:21:47Procurement agentPayment above $500,000Held · CFO approval
09:22:15Mail agentSend contract to external domainHeld · owner approval
09:30:03Support agentGrant itself admin roleDenied · policy
Identity & access

Single sign-on, roles from your directory, least privilege for agents

The platform does not invent a second identity system. People sign in the way they already do, and access follows the roles you already manage.

SSO

SAML 2.0 and OpenID Connect

Sign-in through your identity provider. Multi-factor rules, session length and conditional access stay under your policy.

Directory

Roles inherited, not re-typed

Groups and roles come from Active Directory, LDAP or your identity provider. Leavers lose access when you disable them there.

Granularity

Down to rows and fields

Access is restricted by system, object, row and field. A regional manager sees their region; salary fields stay hidden from those without rights.

Agents

Least privilege by design

Each agent has a declared scope of data and actions. It acts with the intersection of its scope and the user's rights — never the union.

Connectors

One service account per system

Read-only by default. Write rights granted per action, documented and visible in the audit log.

Admins

Separation of duties

Changing an agent's permissions and approving the change are different roles. Every change is logged with who, what and when.

Audit & monitoring

Every query, answer and action — on record

The audit log is the evidence base for your security team, your auditors and your regulators. It records what happened in enough detail to reconstruct any answer or action.

Audit recordExample · illustrative data
timestamp
2026-03-12T09:21:47Z
user
j.martin · finance · SSO
agent
procurement-agent v1.8
request
Pay invoice 4471, supplier new
sources
ERP: invoice 4471 · contract 2025-118
policy
amount > $500,000 → approval
decision
held for approval · CFO
approved_by
a.keller · 09:58:10Z
  • Who asked, from which session and role
  • What the agent answered, and which sources it cited
  • Which actions it proposed, which were taken, and who approved them
  • Policy decisions: allowed, denied, held for approval
  • Administrative changes to agents, roles and connectors
  • Export to your SIEM in standard formats; retention period set to your policy
Monitoring

Alerts for denied actions, unusual query volumes and repeated override attempts can be routed to your SOC. SIEM export is included in the Enterprise and Sovereign packages.

Incident response

When something goes wrong: the process and the clock

Incidents are handled under a written plan agreed with you before go-live. Notification timelines are fixed in the contract so your own regulatory deadlines — such as GDPR's 72 hours for controllers — can be met.

  1. 01

    Detect

    Monitoring, alerts from your SOC, or a report from a user or our engineer.

  2. 02

    Triage

    Severity classified against the agreed scale; the duty engineer takes ownership.

  3. 03

    Contain

    Affected agent, connector or access suspended. Evidence preserved from the audit log.

  4. 04

    Notify

    You are informed without undue delay, with what we know and what we don't yet know.

  5. 05

    Remediate

    Root cause fixed, reference tests re-run, release approved by your side.

  6. 06

    Report

    A written post-incident report with timeline, impact, root cause and actions.

Support and response by package

FoundationEnterpriseSovereign
CoverageBusiness hours24/7 for critical incidents24/7
Critical incident responseNext business hours24/7, per contract1 hour
Named duty engineer——✓
SSO and SIEM export—✓✓
Written post-incident report✓✓✓
Impact and security reviewQuarterlyMonthlyContinuous, embedded team

Package details and annual prices are on the pricing page.

Data lifecycle

From ingest to deletion certificate

Every piece of data the platform touches has a defined path, a retention period and an end.

  1. 01

    Ingest

    Connectors read from your systems with least-privilege accounts. Only the sources agreed for each use case are indexed.

  2. 02

    Process

    Data is encrypted in transit and at rest. Personal data is masked before any external model call.

  3. 03

    Use

    Answers are filtered by the user's rights. Every access is written to the audit log.

  4. 04

    Retain

    Index, conversations and logs are kept for the periods set in the contract, matched to your retention policy.

  5. 05

    Delete

    At the end of the period or the contract, data is deleted within the agreed time and a deletion certificate is issued.

Regulatory alignment

Privacy and AI regulation across your markets

We design the platform to support compliance with the main data-protection and AI laws in Europe, the Americas and Asia-Pacific, and we provide documentation for your DPIA and other assessments. We do not certify compliance — the legal assessment remains yours.

Orientation, not legal advice. Requirements depend on your role, sector and use case.
RegulationRegionWhat reviewers usually askHow we design to support it
GDPREU / EEALawful basis, minimization, processor terms, transfers, DPIAIn-region or on-prem processing, processor agreement, masking, deletion, DPIA input pack
EU AI ActEURisk classification, human oversight, logging, transparency to usersHuman approval enforced in configuration, full logs, AI disclosure in user channels, technical documentation
PIPLChinaLocalization, cross-border transfer rules, sensitive dataIn-country deployment on local models, no calls to foreign APIs, logs and keys in-country
APPIJapanPurpose of use, security measures, transfers abroadPurpose recorded per agent, access control and logs, in-country deployment
PIPAKoreaPurpose limitation, safety measures, cross-border transferOn-prem or air-gapped, field-level access, complete access logs
LGPDBrazilLegal basis, data-subject rights, impact reportIn-country deployment, processing records per use case, deletion on request
Privacy Act & APPsAustraliaUse and disclosure, security, cross-border disclosureAustralian region or on-prem, access control, logs for your privacy impact assessment
CCPA / CPRACalifornia, USNotice, consumer rights, service-provider terms, automated decision-makingService-provider terms, deletion and access support, human review of significant decisions
Sector rulesHealth, finance, public sectorSector-specific confidentiality and record-keeping (e.g. HIPAA-style rules)Deployment inside your accredited environment, retention and access matched to the rule
Due diligence

Vet us before work begins

We'll send the documentation pack under NDA, complete your security questionnaire, and an engineer can meet your security team before the contract is signed.

Architecture

Architecture description

Components, deployment options, network boundaries and data-flow diagrams for your chosen mode.

Threats

Threat model

The full version of the summary above, with controls and residual risks.

Questionnaire

Your questionnaire, completed

In your format, or a standard one your team prefers.

Testing

Penetration-test cooperation

Your testers or your chosen firm test the pilot environment; we fix findings and support the retest.

Privacy

DPA and DPIA input

Data-processing agreement, list of subprocessors, and an input pack for your DPIA or impact assessment.

Operations

Incident and access procedures

Incident response plan, staff access rules and the deletion-certificate template.

We don't hold SOC 2 or ISO 27001 certification. Instead we deploy into environments you control and give your team everything needed to assess us directly.

Request security documentation
FAQ

Questions CISOs ask us

Do you use our data to train models?

No. Frontier models are accessed through enterprise APIs whose terms exclude training on customer data. Local models run inside your infrastructure. Fine-tuning on your corpus happens only in your environment, at your request.

Do you hold SOC 2 or ISO 27001?

No. We say so openly. To compensate, we deploy in environments you control — private cloud, on-premises or air-gapped — and give your team the architecture, threat model, completed questionnaire and access to our engineers, plus cooperation with your penetration test.

Can we hold the encryption keys?

Yes, in private-cloud, on-premises and air-gapped deployments the keys stay in your key management service or HSM. In BlackGust Cloud, keys are managed by BlackGust in the same region; if you must hold them yourself, choose one of the other modes.

Can we run a penetration test?

Yes. We agree scope and timing, your testers or your chosen firm test the pilot environment, we fix findings and support the retest.

How do you stop prompt injection?

We assume it will be attempted. Retrieved content is treated as data, not instructions; inputs are filtered; and, most importantly, agents cannot exceed the user's rights or take risky actions without human approval. A successful injection hits the same walls as any user.

How quickly will you tell us about an incident?

Without undue delay, within the timeline fixed in the contract so you can meet your own regulatory deadlines. In the Sovereign package, critical incidents get a 1-hour response from a named duty engineer.

Which subprocessors are involved?

It depends on the mode. With frontier models, the model provider's enterprise API is a subprocessor; in BlackGust Cloud, so is the hosting provider in your region. In on-premises and air-gapped deployments without frontier models, there are none. The full list is in the DPA.

Can BlackGust engineers see production data?

Only named engineers, for the agreed period, with logged access that is revoked at handover. In air-gapped deployments they work on site under your supervision and access rules.

Can logs go to our SIEM?

Yes. The audit log exports to your SIEM in standard formats, and retention follows your policy. SIEM export is part of the Enterprise and Sovereign packages.

Put us through your security review

Send your questionnaire or ask for the documentation pack. An engineer will walk your team through the architecture and threat model.