Where your data goes — and where it never goes.
This page is written for the person who reviews vendors for a living: your IT lead, your compliance officer, your fractional CISO. It describes the architecture our builds inherit — the same one running a regulated lender’s back office today. Bring your security questionnaire; the answers below are the ones we put in writing.
Five controls, in the order your data meets them.
Most AI vendors ask you to trust their cloud. We built the opposite: a stack where the sensitive thing stays put and every step leaves evidence.
Local models, on your hardware.
For regulated work, the models that read your documents run on a machine in your own building, not someone else’s cloud. In normal operation, nothing about a client file is sent to an outside service. When a cloud model is genuinely the right tool for a workflow, that trade-off is stated in the fixed quote — in writing, before work begins — and you decide.
Deployment: on-prem by default for regulated dataPII is stripped before any model reads a document.
Microsoft Presidio — an open-source PII engine you can inspect yourself — detects and removes names, Social Security numbers, and account numbers first. The model sees the work, not the identity. This isn’t a policy promise; it’s a pipeline stage the document physically passes through.
Engine: Microsoft Presidio · runs before model ingestionEverything stored is encrypted at rest.
Documents, extracted data, and work products are fully encrypted where they sit. A copied disk is a useless disk.
Scope: all stored documents and derived dataEvery action writes to an append-only, tamper-evident log.
Each action the system takes is appended to an audit log secured as a tamper-evident chain: entries can be added, never edited or deleted. When your auditor asks what happened, compliance can prove nothing was altered — not assert it, prove it.
Property: append-only · chained · verifiableA person signs off on every consequential action.
Nothing sends, files, posts, or pays until a person approves it. The system shows its work — what it did, what it’s asking for, the source it relied on — and a person approves, sends it back, or escalates. While a request waits, nothing moves.
Rule: the machine prepares; people decideWhat never happens.
- No client file leaves your network in normal operation on a regulated deployment.
- No model reads raw PII. Identity is stripped before ingestion, not redacted after.
- No action fires on its own. Send, file, post, pay — all of it waits for a human approval.
- No number comes from a model’s memory. Eligibility, credit, price — those come from your systems of record.
- No quiet edits. The audit log only grows; it cannot be rewritten.
- No resold software. We’re vendor-neutral — nothing on this page depends on you buying a product we profit from.
This architecture is running right now.
MARCUS runs the back office of B:Side Capital, a regulated SBA 504 / CDFI lender: 14 AI agents across 7 departments, built from ~840 source documents, entirely on-prem. Every control on this page is a description of that system, published with the client’s written permission — not an aspiration for a future one.
Have a security questionnaire? Send it, or bring your IT reviewer to the free 30-minute assessment. The person answering is the founder who is accountable for the build — and “that control doesn’t apply to your workflow” is an answer we’ll put in writing too. The plain-English version of the cloud-versus-on-prem call is in where your AI data actually goes.
Book the free assessment →What compliance asks.
Something we didn’t cover?
Ask it directly. Security questions land with the founder, not a sales queue.
Ask a security question →01Does our data leave our building?+
For regulated work, no — the models run on your own hardware, and in normal operation no client file leaves your network. That is how MARCUS runs at a regulated SBA lender today. When a cloud model is the right call for a workflow, we say so in the written quote and you decide.
02Do AI models see our customers’ personal information?+
No. Microsoft Presidio detects and removes names, Social Security numbers, and account numbers before any model reads a document. The model sees the work, not the identity.
03How is stored data protected?+
Everything stored is encrypted at rest, and every action the system takes is written to an append-only audit log secured as a tamper-evident chain.
04Can we audit what the system did?+
Yes. The audit log is append-only and tamper-evident: entries can be added but never edited or deleted, so compliance can prove nothing was altered after the fact.
05Can the AI act on its own?+
No. Nothing sends, files, posts, or pays until a person approves it. The system never decides eligibility, credit, or price — those numbers come from your systems of record, never from a model’s memory.
06Has this architecture run in a regulated environment?+
Yes. MARCUS runs the back office of B:Side Capital, a regulated SBA 504 / CDFI lender: 14 AI agents across 7 departments, entirely on-prem. The case is published with the client’s written permission.