Skip to content

Platform / Enclave

A runtime for matters that cannot leave the perimeter

Private-perimeter deployment keeps matter processing and local inference inside the client-approved environment when outbound paths are denied. Governed external model routes remain available for matters with a different control requirement.

Platform overview

Dedicated client boundary

Private-perimeter deployment can run in a dedicated environment for one firm, with the active hosting and isolation controls recorded for that client.

Zero egress when configured

Zero egress applies only where outbound paths are denied and inference runs locally. External model routes are identified as governed egress.

Deployment-specific retention

Working storage and retention controls are configured for the client environment and documented in the deployment record.

Detail

The specifics

Enough for a technical reader to judge fit. The full architecture goes to your reviewers under NDA.

Architecture whitepaper
Deployment
Client-approved infrastructure, including private-perimeter and governed enterprise patterns
Isolation
Process, namespace, and storage separation between runtime, index, and corpus
Verification
Deployment controls are documented and tested in the named client environment
Updates
Runtime and model changes follow the client-approved deployment and change-control process
Monitoring
Audit and observability are governed according to the deployment boundary

Bring one sensitive matter and one hard security question.

We will show you how Sanctum Lex structures the record, challenges the position and fits the deployment boundary your firm requires.