Security and deployment

The strongest claim is not that data is encrypted in transit. It is that the workload does not need a route out at all.

Zero egress by default, and what can add an entry

Nothing on the request path depends on reaching us. The default is zero egress apart from your identity provider, so people can sign in: one allow-list entry, plus one for each provider you enable.

Connected mode adds an outbound-only management channel that your operator opens and closes, recorded in your ledger. Everything else is denied by network policy, and monitoring stays in-cluster.

Egress allow-list what ships before you add a provider

egress:
  - to: your-identity-provider
    purpose: user sign-in
    # plus one per provider you enable

In severed mode the allow-list is empty.

Severed operation is standard, not an upsell

Every tier can run with no management link at all. Severed mode cannot be withheld: a licence that could switch it off would be a remote control for the very property the product guarantees.

What each mode does
Mode Management link What you get
ModeConnected Management linkOutbound only, initiated from your side What you getEverything in severed mode, plus update staging and fleet health
ModePeriodic Management linkEstablished when your operator chooses What you getThe same, on your schedule
ModeSevered Management linkNever established What you getInference, retrieval, policy, audit and evidence generation, in full

In severed mode, inference, policy and the ledger continue on virtual keys. There is no session cache to fall back on, so a session request fails closed with a stated reason, as does a new browser sign-in.

The licence cannot switch you off

The licence is a signed, time-bounded file validated on your own hardware against a public key pinned into the software we ship. There is no phone-home, no heartbeat and no kill switch.

Expiry is not an outage. Inference continues, and the expiry shows in the operator view to be settled commercially, not as an incident.

Secrets and access

Secrets are never committed: a deployment that would carry one is refused, not warned about. Key material is generated outside the repository.

The audit ledger is append-only; its writer role holds insert and select only.

Retention by stream

Keeping everything forever is not a security posture; it is an exposure.

Retention windows, configurable per customer policy
Stream Window What it holds
StreamApplication logs Window30 days What it holdsOperational logs for debugging
StreamSecurity events Window12 months What it holdsAuthentication, key lifecycle and access changes
StreamAudit ledger Window7 years What it holdsEvery request and decision, hash chained

Prompt and completion bodies are not stored by default. Content hashes are. Full content retention is a per-workload change that is itself recorded.

What we retain, and what can leave

We hold no copy of your prompts, completions, documents, golden tasks or ledger. A route to an external provider, in build, is your own configuration and appears in your data-flow document before anything crosses.

The only thing Heliast itself receives is the Derived Aggregate export, if you choose to send it: pseudonymous evaluation metrics with no names or content, held for the subscription term plus 36 months. Declining changes nothing in your licence or support.

Evidence for your compliance work

Controls, audit records and data-flow documentation you can hand to an auditor, a customer or your risk team. They support your obligations; we do not deliver compliance or hold a certification ourselves, and model outputs are not indemnified.

How the request path works

Deployment and hardware

Terraform and Helm, applied into the cluster you control, on premises or in a private data centre: the same commit produces the same estate. We specify and certify the hardware configuration and never resell it.

One estate, every environment

An environment is wherever a model runs. The same admission, comparison and evidence work in each.

The environments an estate can hold
Environment Where it runs Provenance label
EnvironmentYour box Where it runsYour own facility, on hardware you buy, rent or already have. Provenance labelVerified, for weights we byte-checked ourselves.
EnvironmentPrivate cloud Where it runsYour own tenancy, on capacity you already hold. Provenance labelVerified, for weights we byte-checked ourselves.
EnvironmentHosted open-model provider, in build Where it runsTogether, Fireworks, DeepInfra, OpenRouter, Bedrock, Azure, or another provider you enable. Provenance labelProvenance by host attestation, not verified: we cannot byte-check weights on someone else's server, and we do not imply that we did.
EnvironmentFrontier API, in build Where it runsClaude or GPT, through a route you enable. Provenance labelProvenance by host attestation, not verified.

A route to a hosted provider makes it one more environment in your estate, and it is in build: enabled, it adds one entry to your egress allow-list.

The nine stages

Each stage is gated on the one before. A stage that cannot complete does not quietly pass, and a digest mismatch is a security event, not a retry.

  1. Preflight
  2. Hardware acceptance
  3. Infrastructure
  4. Platform
  5. Model staging
  6. Policy
  7. Identity
  8. Smoke tests
  9. Baseline

Sized to the workload, not sold as a tier

We size the configuration to your workload in discovery, before you commit. Capable coding-class open models now run on one 24 GB card, so a first governed workload may not need a rack.

Pilot hardware is sized to evaluate, so it will not hold production concurrency. Production sizing is part of the pilot's recommendation.

What runs today

The demonstration runs on one laptop and signs in through a local identity stub; federation to a commercial identity provider is in build. Every capability's status and evidence is in the capability status table.

Testing these answers against your own estate? Heliast runs a pilot inside your environment, on your policy.

Book a discovery session