TRUST AND ARCHITECTURE

The architecture your CISO, DPO, and procurement team will ask for.

Tenant scoped AI. Zero retention. Partner hosted production. Foundation model traffic guardrailed and audited. The same commitments your buyer’s risk function would write themselves if they were building the platform.

Zero retention architectural seal with flowing data streams suggesting tenant scoped processing without retention.
ZERO RETENTION ARCHITECTURE

Customer data is processed. Not retained.

Inputs are processed inside the customer’s tenant. Outputs route back to the customer. Working memory persists only as long as the active operation. Reviewer dispositions train the tenant model, not the foundation model. Foundation model traffic is guardrailed by tenant policy and logged for audit.

THE BOUNDARYINSIDE YOUR TENANTInputsDocs, policiesTenant scoped AIinterpret · composeOutputsBriefs, draftsCustomer content does not cross the boundary.Inputs, working memory, and outputs all stay inside your tenant.Reviewer dispositions train the tenant model, not the foundation model.Processed, not retained · working memory onlyFOUNDATION MODEL BOUNDARYFoundation modelshared base weightsGUARDRAILguardrailed · logged · non-training only

The three commitments.

01

Tenant scoped AI

Every customer gets a dedicated tenant. Training, learning, reviewer feedback, and policy corpus stay inside that tenant. No cross tenant data flow. The architecture is enforced at the tenant boundary, not at a permission layer that could be misconfigured.

02

Zero retention of customer data

Customer source documents, customer policy text, customer reviewer feedback, and customer outputs are processed and returned. Working memory persists only for the duration of the operation. Long term retention is a deliberate, contracted exception, not a default.

03

Partner hosted production

Production deployments are hosted by the partner of record inside the partner’s environment, the customer’s environment, or a partner managed environment that meets the customer’s hosting requirements. RegLeg™ operates only betas, demos, and proofs of concept.

AI POSTURE

Foundation model traffic is guardrailed, logged, and auditable.

When the platform routes a request to a foundation model, the request is bounded by tenant policy: which models are eligible, which content classes may transit, which jurisdictions are out of bounds, which prompts require human review. The traffic is logged with the prompt, the response, the model, the latency, and the disposition. The log is available to the customer’s audit function.

RegLeg does not say we never train. RegLeg says: tenant scoped training is positive, foundation model interactions are guardrailed, and the audit trail is yours to inspect.

What you can read here. What is partner only.

NOTICE ROUTING

Two addresses. Each gets to the right person.

legal@regleg.com

Routes to the Chief Legal Officer. Legal notices, contract questions, public document clarifications, press, analyst, investor.

security@regleg.com

Routes to the Chief Information Security Officer. Vulnerability disclosures, incident reports, abuse, security questions.

Request the trust package.

A single bundle covers the three architecture commitments, the AI posture, the public documents, and the partner only document index for procurement review.