Embedding Pipeline Service  ·  View 20 of 22  ·  Assurance

Security — Trust Zones

Five zones ordered by exposure, and the fact that a vector belongs in the data zone rather than a cache tier.

Editable source SVG draw.io All views
Untrusted — tenant content, before any parsing Uploaded bytes PDFs, archives, images Connected SaaS payloads Consumer queries Sandbox — least-trusted compute in the system Extraction workers no egress, bounded OCR workers time + memory capped Quarantine typed failure Platform — mTLS between every workload Retrieval gateway Envoy, SVID Chunker Embedding fleet SPIRE OpenBao source credentials Data — tenant-scoped keys, no operator read path Normalised text tenant key Vectors + indexes tenant key Chunk ledger Audit log immutable Authority — never inside our trust boundary Permission authority query-time ACL Keycloak human identity fetched bytes only bound exceeded normalised text ACL check tenant partition short-lived cred Security — Trust Zones and What Crosses Them Risk / gap External / third party Application we own Interface / broker Security / platform Data store synchronous failure / alternate A vector is recoverable information about its source text, so it sits in the data zone under the same controls as the document, not in a cache tier. v 1.0 · owner Data & AI Platform Architecture · date 2026-10

Decisions

  • Extraction and OCR are the least-trusted compute in the system: no egress, bounded in time, memory, nesting depth and expansion ratio, with a typed failure when a bound is hit.
  • A vector is recoverable information about its source text, so vectors and indexes sit under the same controls as the document — including on export.
  • The permission authority is deliberately outside the platform's trust boundary. The platform asks; it does not hold the answer.

Data-zone controls

  • Tenant-scoped encryption keys, with key destruction available as a tenant-level erasure mechanism.
  • No operator read path to chunk text or query text without an audited, time-bounded, purpose-stated grant.
  • Tenant partitioning is part of index addressing, so a cross-tenant query cannot be constructed rather than being filtered out.

Residual risks

  • A decompression bomb that stays inside every declared bound is still a cost attack. The bounds limit damage; they do not eliminate it.
  • Content-hash deduplication across a tenant boundary would open an existence side channel. The design keeps the cache tenant-scoped, at a cost in hit rate.