Security overview

Private AI architecture buyers can inspect.

ToguAI is designed for sensitive environments where documents, embeddings, model runtime, answers, and logs must remain under customer control.

Data boundary

Core operation is designed to run inside the customer environment so documents and outputs do not need to move to a public AI service.

Identity and permissions

Retrieval is shaped by user identity, roles, attributes, and document permissions before answer generation.

Retrieval and citations

Answers are grounded in retrieved sources and include citations so teams can verify important claims.

Prompt-injection handling

Untrusted instructions found inside documents are treated separately from system policy and permission decisions.

Audit logging

Questions, cited sources, refusals, and policy decisions can be logged locally for review.

Retention

Retention behavior is designed to be predictable and aligned with customer governance requirements.

Software and model updates

Update paths should be reviewed during evaluation so restricted and air-gapped environments can plan controlled changes.

Vulnerability reporting

Security reports can be submitted through the responsible disclosure process.

Evaluation material

Security evidence for private review.

A private walkthrough can include deeper material for technical, legal, and security stakeholders.

  • Architecture overview
  • Permission model summary
  • Threat model summary
  • Retention and audit logging explanation
Book a Private Demo