Security
CompanyMind is software that runs inside your perimeter. There is no vendor cloud, no telemetry channel, no support tunnel. Every property on this page follows from where the software runs — which means you can test it on your own network before you believe a word of it.
The perimeter
Your walls arethe security boundary.
CompanyMind does not bring a security boundary of its own for you to evaluate. It inherits yours. Choose where it runs; everything else on this page is a consequence of that one choice.
01
Your datacenter
Bare metal or your own virtualization, on hardware you already own, already rack and already audit.
02
Your VPC
Your cloud account, your subnets, your security groups, your keys. We are never issued a credential to any of it.
03
Air-gapped
A network with no internet route at all. Models and index ship with the deployment and run offline.
Data flow
Everything happensinside the wall.
Ingest, index and answer are all local processes. No step in this diagram requires a packet to leave your network, and no code path exists that would send one.
Ingest
Your sources
Files, chat, email, images, audio, spreadsheets — read from where they already live.
Index
One brain
Parsed, embedded and connected locally. The access control of each source travels with it.
Answer
Cited back
Assembled from retrieved spans, each one traceable to the artifact it came from.
Audit
Every question, every answer, every source consulted — written to your logging stack as it happens.
No outbound path
Model APIs · vendor cloud · telemetry
Not a setting that is switched off. There is no code that dials out.
No inbound path
CompanyMind
No tunnel, no backdoor, no remote support session. We cannot reach your deployment.
The three directions
Egress is zeroby construction.
Zero is not a target we hit or a default we set. It is the only number the architecture can produce, because the thing that would make it larger was never built.
Outbound
Nothing calls home.
No telemetry, no usage analytics, no license check, no crash reporting, no external model API. This is not a checkbox in an admin panel that a future release could quietly flip back. There is no outbound code path to disable, which means there is nothing to leave switched on by mistake and nothing to regress in version four.
VerifyPut it behind a default-deny egress rule and watch nothing break.
Inbound
We have no way in.
We hold no credentials to your deployment. There is no support tunnel, no listening service pointed at us, no vendor account provisioned at install. If you want us in the room during an incident, you bring us in through your own access process, like any other contractor — and you revoke it the same way, without asking us to cooperate.
VerifyCheck your directory after install. There is no account of ours in it.
Air-gap
Offline is the same build.
Models, index and interface ship together and run with no internet route at all. The air-gapped deployment is not a stripped edition with features quietly missing — it is the same software, because nothing in it wanted the internet in the first place. Updates arrive the way everything else arrives on that network: as a signed artifact you carry in, inspect, and choose to install.
VerifyPull the cable. Ask it a question. It answers.
Access control
Your permissions,not a new set of ours.
The failure mode of every knowledge tool is the flattened index: everything vacuumed into one searchable pool, and now a question from the wrong desk returns the board deck. CompanyMind does not build that pool.
- Every indexed span carries the access control of the artifact it came from.
- Retrieval filters on the asker’s identity before a single span reaches the model.
- Identity comes from your directory — your groups, your roles, your revocations, resolved at query time rather than copied at install.
- A person who could not open the file cannot get an answer built from it. It does not surface in the citations, because it was never retrieved.
Retrieval · filtered by asker
asker: j.reyes · group: analysts
- q3_pricing_memo.docxretrieved
- risk_committee_notes.mdretrieved
- board_deck_2026.pptxnot cleared · never read
Nothing is widened. Nothing is flattened.
A user’s view of the brain is exactly the view they already had of the underlying systems. Revoke someone in your directory on Friday and the brain has forgotten them by the next question.
Audit
Every question isa logged event.
Ask, answer, sources, identity, timestamp. Written into your logging stack, in your format, on your schedule — queryable by your auditors without filing a request with us.
- What is logged
- The question asked, the answer returned, every source span retrieved to build it, the identity that asked, and when.
- Where it lands
- Your SIEM, your log pipeline, your storage. It is your data on your disk from the moment it is written.
- How long it lives
- Your retention schedule. We have no opinion about it and no mechanism to enforce one.
- Who can read it
- Whoever your policy says. We are not on that list, and there is no path by which we could add ourselves.
Inheritance
Your controlsalready cover it.
Software running inside your environment falls under the controls you already run that environment with. There is very little new to evaluate here — which is the entire point of building it this way.
Identity & access
Your IdP, your SSO, your groups, your joiner-mover-leaver process. CompanyMind authenticates against what you already run instead of standing up a user store beside it.
Network policy
Your segmentation, your firewall rules, your default-deny egress. It sits inside them like any other internal service, and it does not ask for an exception.
Key management
Your KMS or HSM. Data at rest is encrypted with keys you hold and rotate on your cadence. We never see them and could not use them if we did.
Logging & monitoring
Your SIEM ingests its logs. Your alerting covers it. Your on-call sees it on the same board as everything else you run.
Backup & recovery
It is your VMs and your volumes. Your existing backup, restore and DR runbooks apply to it unchanged.
Change management
Releases are artifacts you accept, stage and roll out on your schedule. Nothing updates itself, because nothing can reach out to find an update.
On your obligations
If your obligations run through HIPAA, GLBA, DORA, PCI DSS or a regulator’s own residency rules, they attach to the environment you already operate and already evidence. Running CompanyMind inside that environment keeps it within the boundary those obligations already cover, instead of opening a second boundary that needs its own answer, its own vendor questionnaire and its own exception. The obligation stays yours. The deployment model is built so that meeting it does not require you to make a special case for us.
Disclosure
What we arenot claiming.
You are going to ask. So here it is first, in our own words, before you have to drag it out of us on a call.
We hold no certifications.
No SOC 2, no ISO 27001, no HIPAA attestation, no FedRAMP authorization. CompanyMind is pre-launch. A vendor page that implies otherwise this early is telling you something about the vendor.
We have no customers to point at.
No logos, no case studies, no testimonials, no anonymous “leading global bank”. We are recruiting our first design partners now. When there are references, they will be real and named with permission.
We will not call it unbreakable.
Software has bugs and ours will too. The honest claim is narrower and more useful: there is no outbound path, no vendor access and no shared tenancy — so the blast radius of our mistakes stops at your perimeter, where your controls are already standing.
None of this is a benchmark.
No accuracy percentage, no latency figure, no retrieval score. We have not earned those numbers, and the ones published before a first deployment are marketing arithmetic.
A certification is a statement about a company. An architecture is a statement about a system.
We would rather hand you the second one and let you check it yourself — and when the audits do come, they will describe a system that already worked this way.
Design partners
Send us yoursecurity questionnaire.
We would rather answer the hard version early. If you are working out whether this could survive your review, bring the review — the topology, the threat model, the questions your auditors will ask in month nine. We are choosing a small number of design partners in regulated environments, and this is exactly the conversation we want to be in.
A reply from an engineer, not a sales sequence.