Data boundary
Core operation is designed to run inside the customer environment so documents and outputs do not need to move to a public AI service.
Security overview
ToguAI is designed for sensitive environments where documents, embeddings, model runtime, answers, and logs must remain under customer control.
Core operation is designed to run inside the customer environment so documents and outputs do not need to move to a public AI service.
Retrieval is shaped by user identity, roles, attributes, and document permissions before answer generation.
Answers are grounded in retrieved sources and include citations so teams can verify important claims.
Untrusted instructions found inside documents are treated separately from system policy and permission decisions.
Questions, cited sources, refusals, and policy decisions can be logged locally for review.
Retention behavior is designed to be predictable and aligned with customer governance requirements.
Update paths should be reviewed during evaluation so restricted and air-gapped environments can plan controlled changes.
Security reports can be submitted through the responsible disclosure process.
Evaluation material
A private walkthrough can include deeper material for technical, legal, and security stakeholders.