Security & data sovereignty
Your knowledge never leaves the building
CortexEleven is private AI infrastructure. Documents are scanned, OCR'd, indexed and queried inside the boundary you choose, with no third-party model provider in the loop. For organisations handling sensitive records, sovereignty is the foundation, not an add-on.
How we protect your data
Security built in at every layer
01 / 06
Runs where you choose
Deploy in a private cloud tenant, on an on-premise appliance, or fully self-hosted on your own network. Your documents and models sit inside the boundary you set.
02 / 06
Data stays yours (BYOS)
Bring Your Own Storage: files remain in your own storage provider. We never hold your documents, and cloud tenants retain only obfuscated metadata and reference indexes.
03 / 06
No third-party model access
Your knowledge is never sent to an external AI provider. Models run within your deployment, so sensitive records are never exposed to train someone else’s system.
04 / 06
Role-based access control
Every person sees only what they are cleared to. Results are permission-scoped by role, department and document tier, enforced server-side.
05 / 06
Grounded, cited answers
Every AI answer traces back to the exact source document and page, so nothing is taken on trust and everything can be verified.
06 / 06
Immutable audit trail
Sensitive actions, including document deletions, are captured in an append-only, 7-year audit log that shows who did what, and when.
Data residency
You decide where your data lives
The platform is identical across deployments. What changes is the boundary, and you can prove exactly where every document sits.
01
Managed cloud
Single-tenant, Australian-hosted (Sydney region). Files stay in your storage; we hold obfuscated metadata and reference indexes only.
02
On-premise appliance
Documents, indexes and models all run on your premises. Only encrypted device health and update information is sent back, over a secure management link.
03
Sovereign / self-hosted
Runs fully offline on your own network - no internet connection, and nothing is sent back to us, not even device health data. No external or vendor access. Your models, your keys, your infrastructure.
Controls & practices
The safeguards, in short
- Encryption in transit and at rest
- Least-privilege, role-based permissions
- Server-side enforcement, not UI-only
- Append-only, tamper-evident audit logs
- Content silently filtered by clearance
- Data-residency guarantees per deployment
- Typed-confirmation on destructive actions
- Regular updates managed without data access
Turn your archive into a searchable knowledge hub
See CortexEleven digitise and search a sample of your own records - on your hardware, in your environment.
CLOUD · APPLIANCE · SOVEREIGN