Security

Security and Data Protection

Zero-Trust architecture. End-to-End encryption (VPN + TLS 1.3 in transit, AES-256 at rest) and 100% private models with zero internet egress.

Data protection before the AI model

1 Request

Question, document or agent action

2 RBAC

Roles, groups and privileges

3 Documents

Collection, folder and secrecy level

4 PII filter

IDs, accounts, names, phones, secrets

5 Masking

Token replace or stop the request

6 AI model

Masked content only, by policy

At-Rest & In-Transit Encryption

Databases, vector indexes and documents are encrypted with AES-256, and communication with the Gateway flows through a VPN + TLS 1.3 tunnel.

Granular RBAC

Employees see only the documents and agents they are explicitly authorized for within their unit.

PII Masking

Automatic detection and pseudonymization of personal data (IDs, passports, accounts, emails) before anything is forwarded.

Data Blocking

Strict rules that fully stop a request if it contains highly confidential keywords or classified numbers.

Immutable Audit & Logging

A detailed audit of who searched which contract, when, and why — stored in a cryptographically protected log.

Private Mode Protection

Activating the konekt-private model fully blocks cloud communication and runs inference locally.

What NEVER leaves your server What may reach a model (Policy only)
Original PDF contracts, scans, and technical drawings A temporary anonymized chunk needed for the answer
Document index, search, and internal relational databases Pseudonymized text with PII placeholders
User accounts, passwords, and RBAC permissions Token usage and budget parameters
PII mechanisms and blocking rules NEVER ANYTHING

Need a security assessment for AI?

Our cybersecurity and compliance specialists will provide a detailed report and a compliance plan.

Request a security analysis