Glossary

The words a buyer meets in a discovery session or a pilot proposal, in plain terms.

Terms

Admission gate
The executable check every model passes before it enters the catalogue. The canonical licence text is pinned by SHA-256 on an allow-listed source, the identifier comes from the licensor's own repository metadata, an added-clause screen runs over sibling policy files, and the provenance chain is recorded. The output is a provenance artefact with a status.
Provenance artefact
One named, versioned document per model: licence and evidence path, canonical-text pin, added-clause screen, provenance chain, export screen, hardware fit, attestation version, and a status of admitted, held or rejected. It is the answer to "can we use this?".
Provenance label
What the evidence says about the weights behind a served model. Verified means we byte-checked the weights ourselves. A hosted route is in build and is labelled provenance by host attestation, not verified, because weights on someone else's server are not bytes we hashed.
Audit ledger
An append-only table that records each request, the decision taken and the policy revision that permitted it.
Chain
Each ledger row carries a hash of the row before it. Changing or removing a row breaks the chain at that point.
Anchor
A signed digest of the current chain head, exported outside the ledger, so rows removed from the end of the chain are detectable by anyone who cannot also rewrite the anchor.
Fail closed
A rule for dependency failure: when policy or a required service cannot be evaluated, the request is denied rather than allowed.
Execution environment
Where a model runs: your own box, your private cloud, a hosted open-model provider, or a frontier API, the hosted and frontier routes in build. A hosted provider is one more environment in the estate, governed like any other and priced as an environment; hosted provider and frontier API routes are in build, and the price line marks them when available.
Golden dataset
A fixed set of tasks with known-good results, used to score a candidate model the same way every time.
Inference
A model producing an output from an input. The ledger records each one with token counts, model digest and policy revision.
Model entitlement
The rule that says which models a person or a group may call, and under what budget.
Policy revision
The version of policy that applied to a request, named in the audit row. It is the commit that produced the loaded rules.
Retrieval
Fetching passages from your own knowledge sources to place in a prompt. Results are filtered by the caller's entitlements before ranking.
Severed mode
Operation with the management link absent. Inference, policy and audit continue on virtual keys; there is no session cache, so a session request and a new sign-in both fail closed with a reason.
Severability
The property that the stack keeps working when the management link is absent. Nothing in the licence can withhold it.
Virtual key
A per-person or per-team credential the gateway validates on every request and can revoke immediately, with no cache.
Zero egress
No route out of the environment except what you allow yourself. The egress allow-list is one identity-provider entry plus one entry for each provider you enable, and you generate both; with no provider enabled it is one entry long.
Prefix caching
Reusing the computed state for a prompt prefix that repeats. It is entitlement-safe here because retrieved context differs by subject, so prompts diverge before any user data is cached.
Pilot
The Estate Pilot is a fixed scope over 8 to 12 weeks, on evaluation hardware, built to produce evidence rather than to carry production traffic. It is not a production deployment, and it is priced to cover its own cost: severability means the pilot may be all we get.

Still have questions about a term above? Heliast runs this inside your environment, on your policy.

Book a discovery session