SECURITY ARCHITECTURE BLUEPRINT

Defense-in-Depth
Architecture.

End-to-end encryption, strict RBAC, and optional air-gapped deployment. Your data remains sovereign.

AES-256 ENCRYPTION
TLS 1.3 INGRESS
AIR-GAP CAPABLE
TLS 1.3
VPC FIREWALL

Architectural Pillars

Enterprise SSO

INTEGRATED

Full support for OIDC and OAuth 2.0. Seamless integration with Azure AD, Okta, and on-premises identity providers.

REF: IAM-OIDC

GDPR

Native

Architecture enforces strict data residency and supports 'Right to Erasure' workflows.

REF: GDPR

SOC 2 Type II

Audit Ready

Controls and logging infrastructure prepared for audit.

REF: SOC2

Data Residency

GERMANY / ON-PREM

Managed hosting via Hetzner (Germany) or complete self-hosting on your own infrastructure. Fully offline capable (no internet required).

REF: HYBRID-DEPLOY

HIPAA

Capable

Can be configured for PHI processing in isolated environments.

REF: HIPAA

CCPA

READY

Architecture supports California Consumer Privacy Act requirements for data handling.

REF: CCPA

Secure Inference Pipeline

Inference occurs locally. No external API calls for proprietary data.

User

Corporate Device

TLS 1.3 Tunnel

NO EGRESS

PrivaCorp Node

VPC / On-Prem

Private Network

Local LLM

Inference Engine

PII Detection & Masking

Sensitive data is automatically detected and masked before AI processing.

Enterprise

SaaS + ON-PREM

PrivaCorp uses its PII Microservice to detect and mask emails, phones, SSNs, credit cards, names, locations, and medical records.

DETECTION CAPABILITIES
EMAILPHONESSNCREDIT_CARDNAMELOCATIONMEDICAL

Standalone

OFFLINE

PrivaCorp utilizes local Regex + ML.NET engines for 100% offline PII detection. No data ever leaves your device.

OFFLINE DETECTION
EMAILPHONESSNCREDIT_CARDIP_ADDRESSNER

Conditional Filtering

Trust where it matters. We bypass PII masking for local models like Ollama to give your AI 100% context and accuracy. You hold the keys. Easily toggle trust for any endpoint. For ultimate sovereignty, keep your models close and your data closer on your own infrastructure.

High-Performance RAG Architecture

Encrypted Vector Storage

Billion-scale Milvus/pgvector instance with AES-256 encryption at rest. Zero-knowledge architecture for stored embeddings.

Local Ingestion Pipeline

Proprietary parsers process PDFs/Office docs entirely within your VPC. No data is ever sent to external OCR APIs.

RBAC & Access Logs

Granular document-level permissions ensure users only retrieve context they are authorized to see.

Frequently Asked Questions

Does PrivaCorp train on our data?

No. Your data is processed locally within your sovereign environment (Self-hosted or Managed) and is never sent to PrivaCorp servers. We have zero visibility into your inference data.

What happens if we cancel our subscription?

Since the model runs on your infrastructure (or dedicated instance), you retain full access to your data. The proprietary inference engine license will expire, but your data remains yours.

How do you handle model updates?

We provide encrypted model weights via a secure container registry. You can pull updates and deploy them to your air-gapped environment manually or via CI/CD.

Is the system air-gap compatible?

Yes. The entire stack is designed to run without internet access. Updates can be transferred via secure physical media if required.

What are the hardware requirements?

For self-hosted inference, we recommend HPC Servers equipped with NVIDIA RTX 6000 (Blackwell) GPUs. For enterprise-wide concurrency, the architecture scales to NVIDIA DGX B200 clusters. Alternatively, we provide fully managed, sovereign infrastructure where no hardware investment is required.

Can we integrate this with internal tools?

Yes. PrivaCorp exposes a full OpenAI-compatible REST API. It works natively with LangChain, Microsoft Semantic Kernel, and custom Python scripts.

What is the typical deployment timeline?

From contract to live inference usually takes less than 48 hours. Our engineering team assists with the initial Docker orchestration.

Do you offer SLA-backed support?

Enterprise plans include 24/7 engineering support with guaranteed response times for critical incidents.

Ready to secure your infrastructure?

Join the pilot program. Engineered in Linz.