AI Executive Office — CXO Assistant Platform (On-Premises) · View 28 of 30 · 7 · Assurance
How it is enforced
- By physics first, then by policy. There is no cloud plane to leak into: every process runs on hardware the customer owns and can point at. Admission control refuses any workload without a residency label, and the perimeter firewall denies egress that is not on the allow-list, so an air-gapped deployment is a configuration rather than a different architecture
- Per-tenant keys held in the customer’s own HSM and issued through Vault, with no vendor copy anywhere. Revoking the key makes the data unreadable, which is a meaningful sovereignty guarantee rather than a contractual one
- Break-glass vendor access is requested, approved by the customer, time-boxed and screen-recorded
What never leaves
- Prompts and completions, retrieved passages, business data and KPIs, decision and audit records
- What does leave, explicitly: service telemetry with no customer content, inbound threat intelligence, and build-time package feeds
- Each item maps to a named national information-assurance control with evidence, produced as a control matrix during detailed design
The open risk
- GPU availability is the constraint most likely to break this architecture: accelerators are ordered months ahead and a dense rack may exceed what the hall can power or cool. Three fallbacks are pre-agreed: run a smaller open-weight model on the accelerators actually available and accept a capability gap; place inference on a customer-approved hosted endpoint under a written data-boundary commitment; or defer the AI capability while the data platform ships. The choice is the customer's and belongs in the contract, not in a diagram