AlifZetta
Security · Enterprise Posture

Security posture.

AlifZetta is deployable inside government, healthcare, defence, and finance because sovereignty is architectural, not a checkbox. Below is the full security posture — twelve properties enterprises verify during procurement.

Padam Sundar Kafle
Padam Sundar Kafle
Founder, AlifZetta Superintelligence
·

Sovereignty is the foundational security property

Every AlifZetta security property flows from one architectural commitment: the stack runs on customer hardware with zero external LLM API calls at inference. That commitment is not a feature — it is what disqualifies most of our competitors from the verticals where compliance actually matters.

Twelve properties enterprise buyers verify

Sovereign inferenceAlifZetta makes zero external LLM API calls at inference. No OpenAI, Anthropic, Google, or third-party AI vendor in the inference path. Customer data never leaves the customer perimeter.
Air-gapped deploymentThe full stack — CLLM + NEXUS + LATTICE + PRISM — runs on the customer's own hardware without any outbound network dependency. Air-gapped deployments are a supported configuration.
Auditability by designEvery answer ships with a PRISM proof-tree — a walkable graph of cited NEXUS entities. Auditors, compliance officers, and regulators can independently re-execute any answer end-to-end.
Data lineageEvery NEXUS entity is timestamped, versioned, and stored as human-editable DTL under git. Full data lineage: what was known, when, from where.
Deterministic retrievalSame query returns the same subgraph, every time. Reproducibility satisfies model-risk validation requirements (SR 11-7, MiFID II, EU AI Act).
No customer-data trainingAlifZetta does not train models on customer data. The paradigm is substrate-time, not training-time — customer knowledge lives in the customer's NEXUS, not in any AlifZetta model weights.
Encryption in transit and at restTLS 1.3 for all API traffic; disk-level encryption via customer's OS (LUKS, dm-crypt, BitLocker) — no additional AlifZetta key material required.
Access controlRole-based access to NEXUS entities via the customer's existing IAM. AlifZetta ships with a reference RBAC layer; can integrate with LDAP, OIDC, SAML, or bespoke systems on request.
Rate limiting + WAFPer-IP and per-key rate limits deployed at the nginx layer. WAF ruleset covers OWASP top-10 and PII redaction in outbound responses.
Vulnerability disclosuresecurity.txt published at /.well-known/security.txt. Responsible disclosure to padam@axz.si with 90-day coordinated disclosure timeline.
Sovereign supply chainAlifZetta runs on commodity CPU — no rare-earth GPU supply-chain dependency. Deployable on any silicon your organisation can lawfully procure.
Open code pathThe critical inference path is open and inspectable. Not a black box. Not proprietary. If a customer's security team wants to audit line-by-line, they can.

What we are honest about not having yet

AlifZetta does not yet hold SOC 2 Type II, ISO 27001, or HITRUST CSF certifications. Those are on the roadmap for the 2027 enterprise-partnership tier. In the meantime, we structure pilots with individually-negotiated security agreements — DPAs, BAAs, on-premise deployment clauses — that reflect the sovereign posture already inherent to the architecture.

For customers whose procurement requires a specific certification we do not hold, we are transparent about the gap and work with the customer's security team to bridge it via contractual controls (right-to-audit, source-code escrow, on-site deployment supervision).

Responsible disclosure

Report a security concern: email padam@axz.si with subject line SECURITY:

Coordinated disclosure window: 90 days from initial report

PGP key on request. No bug bounty programme currently — but every responsible disclosure receives a public acknowledgement on this page (with reporter permission) and, where appropriate, a founder-signed letter of appreciation.

Independent verification

Every security claim on this page is falsifiable. Run grep against our production tree for 'openai', 'anthropic', 'gemini' — zero hits, sovereign inference confirmed. Query the live demo under a wall-power meter — Green Intelligence energy claims confirmed. Delete a cited NEXUS entity and watch the corresponding answer degrade — PRISM proof-tree property confirmed. We invite the audit.

Book a security-review call

Your CISO team + our founder. 45 minutes. Cover the twelve properties, negotiate the pilot security agreement, agree on the audit surface.

Email padam@axz.si → See pricing →