SECURITY AND PRIVACY
Data stays within the organization's own boundaries
01 /
The model runs on the organization's hardware
ARCH deployments run on the organization's own infrastructure (on-premises). Retrieval, inference, and generation all take place within this boundary; organizational data is never sent as a prompt to an outside model.
A single processing pipeline runs inside the wall around the organization's boundary; answers are generated only from the document set inside, and no model calls go out. Elements:
- Organization boundary: on-premises perimeter wall
- Processing pipeline: retrieval · inference · generation
- Document set: closed knowledge boundary
- Access lines: same question, two document sets
- Audit trail: question → document → approval
- Retention and destruction: automatic at end of period
- External model: no call crosses the boundary
02 /
01
On-premises operation
Deployment takes place on the organization's own hardware. Data does not leave the organization's network to be processed; no model calls go outside.
02
Closed knowledge boundary
An answer to a question is generated only from the organization's own document set. The model does not use general knowledge outside that set as a source — and it can be shown that it does not.
03
Who can see what
Access is defined at the document and record level. A document a user cannot see does not appear in the answer to that user's question either.
04
Audit trail
Who asked what, which document the answer was generated from, who approved what — all traceable after the fact. The audit trail is not a deletable side record; it is the system itself.
05
Retention and destruction
The retention period for each data type is defined at deployment, and destruction runs automatically at the end of the period. The period is as long as legislation requires; no longer.
06
Certification
Our information security and quality management systems are certified. Certificate details are shared on request through our contact channels.
03 /
Not a wrapper application
Many "AI" products on the market are wrappers that pass the user's data to a third-party model and display the returned answer in their own interface. In a regulated organization, this creates two problems: data leaves the organization's boundary, and it cannot be shown which source the answer came from.
ARCH does not use this model. Deployment is on the organization's hardware, the knowledge boundary is the organization's document set, and the source of every answer is recorded.
Certification
CERTIFICATE
ISO 27001:2022
Information security management system
CERTIFICATE
ISO 9001:2015
Quality management system
Let's discuss deployment boundaries
Let's write down together which data sits where, who holds which permission, and how the audit trail is kept.