Security built for businesses that answer to clients
A credible security review separates what the product is designed to do from what must be confirmed in a specific deployment. Here are the controls we configure and the details we document with you.
Deployment boundary
A dedicated Azure environment is the starting point.
- Private GPT is provisioned in a Microsoft Azure environment dedicated to the customer deployment.
- Approved documents, indexes, conversation context, and logs are placed according to the architecture agreed for that environment.
- Region, residency, backup, and deletion requirements are reviewed during scope and documented before launch.
Encryption and secrets
Controls are configured and recorded for the deployment.
- Azure-managed encryption at rest is used for supported storage services in the deployment.
- Traffic is configured to use TLS across the application, connected services, and selected model endpoints.
- Application secrets and credentials are handled through managed secret storage rather than embedded in application code.
Identity and access
Permissions are mapped to approved users and sources.
- Role based access can scope retrieval to the sources and workflows each approved group may use.
- Company identity integration and offboarding behavior are configured around the customer's selected login system.
- Available logging, administrator access, and review responsibilities are defined in the deployment scope.
Model-provider data handling
The provider boundary is reviewed instead of hand-waved.
- A configured model call may include the user's request and selected excerpts needed to generate an answer.
- The model provider, endpoint, retention terms, training terms, region, and relevant settings are selected and documented for the deployment.
- Provider terms and settings can change, so the operating plan identifies who reviews changes and when.
Designed to support a real security review
Customers may need to answer client questionnaires, insurer reviews, contract requirements, or internal control checks. A Private GPT proposal can document the Azure boundary, stored data, encryption, identities, permission groups, connected sources, logging, model endpoints, provider terms, and operating responsibilities that apply to the deployment.
Those mechanisms can support a broader security or compliance program, but they do not by themselves certify a customer or make every use case compliant. Your reviewers should evaluate the documented design against your contracts, policies, and legal obligations.
Curious what deployment looks like end to end? Read how a private AI deployment works, inspect the published K3 Technology case study, or use the AI data handling policy workbook, or work through the private AI vendor checklist, or see how single tenant AI differs from multi tenant before reviewing the managed-service responsibilities.
Evidence path
Review the claim, mechanism, and responsibility together
Customer context
The existing attributed K3 statement and deployment story.
Review →Request path
Where access, retrieval, provider handling, and review occur.
Review →Internal policy
A workbook for approved tools, data classes, access, and incidents.
Review →Scoped proposal
The inputs used to define controls, support, timeline, and pricing.
Review →Bring your security questions
Book a meeting to review where data is stored, what crosses the model-provider boundary, who can access each source, what is logged, and what happens when the service ends.