Security is the architecture. Not a feature.

    Read-only connectors. Single-tenant private LLM. Every inference logged and traceable to source.

    Last updated June 2026.

    SOCSOC 2 Type II
    HIPAA-Certified
    GDPR-Certified
    awsPowered by AWS Bedrock

    SOC 2 Type II report available under NDA. HIPAA BAA and GDPR DPA available on Enterprise.

    Encryption & transport

    At rest
    AES-256
    In transit
    TLS 1.2+
    Key management
    AWS KMS (customer-managed on Enterprise)

    Access & audit

    Access model
    Role-based (RBAC)
    Data boundaries
    Row-level security at the storage layer
    Audit trail
    Immutable, exportable, CloudTrail-ready
    Read/write
    Read-only connectors

    Model & data handling

    Inference
    AWS Bedrock, single-tenant instance
    Third-party models
    None. No OpenAI, no shared endpoints.
    Training
    Zero training on customer data
    Data pooling
    Never. Knowledge Graph isolated to tenant.

    Read-only. Single-tenant. Never trained on.

    SIGNLD connects to your systems read-only. Nothing is written back, and nothing is copied into a shared store. The Knowledge Graph built from those connections is isolated to your tenant: it is not pooled with other customers, not sold, and not exposed to any model provider for training.

    Private LLM on AWS Bedrock.

    All inference runs on a single-tenant AWS Bedrock instance. There are no third-party AI APIs in the path, no OpenAI, and no shared inference endpoints. AWS contractually guarantees that inputs and outputs are never used to train or improve foundation models.

    Every inference logged.

    Each query records a timestamp, the user identity, the model invoked, and the source records cited in the answer. Logs are immutable and exportable, and every figure in a decision brief traces back to the system it came from. Audit output is CloudTrail-ready for your own SIEM.