Answers for your security reviewer.
The questions IT and security teams raise — answered from the architecture and the DPA, not from marketing.
What is ephemeral execution?
Each request runs in its own short-lived environment: the model loads, serves the request, and the environment is destroyed when the session closes. Prompt, context, and generated tokens live in RAM-only scratch — no persistent disk is attached.
How is zero retention enforced?
Execution paths are engineered so that prompts, responses, and uploaded document contents are not written to durable storage within the boundaries Privileged controls. Only payload-free metadata (request ID, token counts, latency, status) is retained. Persistent workflows are opt-in and customer-configured.
Do you train on our data?
No — contractually and by construction. The DPA prohibits using customer data to train, fine-tune, or evaluate any model, and because execution data does not persist by default, there is nothing to train on.
Can we whitelist a static egress IP?
Yes. Outbound traffic exits through controlled, static egress with a fixed infrastructure identity your firewall can whitelist. Default egress posture is deny unless a destination is explicitly allowed.
How is tenant isolation handled?
Isolation is enforced at multiple layers: org and project scoping on every record, database row-level security, and single-tenant runtime environments. Privileged offers graduated isolation classes; we describe the class actually provisioned rather than advertising a stronger level than is implemented.
How long does the DPA take?
The goal is days, not months — one agreement with Privileged instead of separate zero-retention negotiations with every cloud and model vendor.
What about custom and private models?
Host private and fine-tuned models in isolated environments, or run open and Privileged-hosted models through one logical identifier. Weights stay yours and are never used for training. LoRA adapters are supported.
What encryption do you support?
TLS 1.3 in transit, and encryption at rest for stored configuration and model artifacts. Customer-managed keys are available for stored data.
Are you SOC 2 or ISO 27001 certified?
Not at this time. The architecture is built to make those controls achievable, and we can walk security teams through the current posture — but Privileged does not claim certifications it has not completed.
Is access available now?
Early access is open to a limited set of firms and legal-engineering teams. Request access at hello@privilegedinfra.com.