Security and deployment
The strongest claim is not that data is encrypted in transit. It is that the workload does not need a route out at all.
Zero egress by default, and what can add an entry
Nothing on the request path depends on reaching us. The default is zero egress apart from your identity provider, so people can sign in: one allow-list entry, plus one for each provider you enable.
Connected mode adds an outbound-only management channel that your operator opens and closes, recorded in your ledger. Everything else is denied by network policy, and monitoring stays in-cluster.
Egress allow-list what ships before you add a provider
egress:
- to: your-identity-provider
purpose: user sign-in
# plus one per provider you enable
In severed mode the allow-list is empty.
Severed operation is standard, not an upsell
Every tier can run with no management link at all. Severed mode cannot be withheld: a licence that could switch it off would be a remote control for the very property the product guarantees.
| Mode | Management link | What you get |
|---|---|---|
| ModeConnected | Management linkOutbound only, initiated from your side | What you getEverything in severed mode, plus update staging and fleet health |
| ModePeriodic | Management linkEstablished when your operator chooses | What you getThe same, on your schedule |
| ModeSevered | Management linkNever established | What you getInference, retrieval, policy, audit and evidence generation, in full |
In severed mode, inference, policy and the ledger continue on virtual keys. There is no session cache to fall back on, so a session request fails closed with a stated reason, as does a new browser sign-in.
The licence cannot switch you off
The licence is a signed, time-bounded file validated on your own hardware against a public key pinned into the software we ship. There is no phone-home, no heartbeat and no kill switch.
Expiry is not an outage. Inference continues, and the expiry shows in the operator view to be settled commercially, not as an incident.
Secrets and access
Secrets are never committed: a deployment that would carry one is refused, not warned about. Key material is generated outside the repository.
The audit ledger is append-only; its writer role holds insert and select only.
Retention by stream
Keeping everything forever is not a security posture; it is an exposure.
| Stream | Window | What it holds |
|---|---|---|
| StreamApplication logs | Window30 days | What it holdsOperational logs for debugging |
| StreamSecurity events | Window12 months | What it holdsAuthentication, key lifecycle and access changes |
| StreamAudit ledger | Window7 years | What it holdsEvery request and decision, hash chained |
Prompt and completion bodies are not stored by default. Content hashes are. Full content retention is a per-workload change that is itself recorded.
What we retain, and what can leave
We hold no copy of your prompts, completions, documents, golden tasks or ledger. A route to an external provider, in build, is your own configuration and appears in your data-flow document before anything crosses.
The only thing Heliast itself receives is the Derived Aggregate export, if you choose to send it: pseudonymous evaluation metrics with no names or content, held for the subscription term plus 36 months. Declining changes nothing in your licence or support.
Evidence for your compliance work
Controls, audit records and data-flow documentation you can hand to an auditor, a customer or your risk team. They support your obligations; we do not deliver compliance or hold a certification ourselves, and model outputs are not indemnified.
Deployment and hardware
Terraform and Helm, applied into the cluster you control, on premises or in a private data centre: the same commit produces the same estate. We specify and certify the hardware configuration and never resell it.
One estate, every environment
An environment is wherever a model runs. The same admission, comparison and evidence work in each.
| Environment | Where it runs | Provenance label |
|---|---|---|
| EnvironmentYour box | Where it runsYour own facility, on hardware you buy, rent or already have. | Provenance labelVerified, for weights we byte-checked ourselves. |
| EnvironmentPrivate cloud | Where it runsYour own tenancy, on capacity you already hold. | Provenance labelVerified, for weights we byte-checked ourselves. |
| EnvironmentHosted open-model provider, in build | Where it runsTogether, Fireworks, DeepInfra, OpenRouter, Bedrock, Azure, or another provider you enable. | Provenance labelProvenance by host attestation, not verified: we cannot byte-check weights on someone else's server, and we do not imply that we did. |
| EnvironmentFrontier API, in build | Where it runsClaude or GPT, through a route you enable. | Provenance labelProvenance by host attestation, not verified. |
A route to a hosted provider makes it one more environment in your estate, and it is in build: enabled, it adds one entry to your egress allow-list.
The nine stages
Each stage is gated on the one before. A stage that cannot complete does not quietly pass, and a digest mismatch is a security event, not a retry.
- Preflight
- Hardware acceptance
- Infrastructure
- Platform
- Model staging
- Policy
- Identity
- Smoke tests
- Baseline
Sized to the workload, not sold as a tier
We size the configuration to your workload in discovery, before you commit. Capable coding-class open models now run on one 24 GB card, so a first governed workload may not need a rack.
Pilot hardware is sized to evaluate, so it will not hold production concurrency. Production sizing is part of the pilot's recommendation.
What runs today
The demonstration runs on one laptop and signs in through a local identity stub; federation to a commercial identity provider is in build. Every capability's status and evidence is in the capability status table.
Testing these answers against your own estate? Heliast runs a pilot inside your environment, on your policy.
Book a discovery session