Security & Sovereignty

Intelligence that never leaves your perimeter.

For a flag carrier, a ministry, a bank under residency law or a firm holding privileged material, “we send your data to someone else's cloud” is a disqualification. Limen runs the models inside your boundary, so the data never leaves in the first place.


01 / 02, The security model

In-perimeter models

Domain-adapted models served on hardware you control. No third-party inference endpoint to subpoena, breach, or re-price.

Air-gapped option

A deployment topology with no route to the public internet at all, model updates packaged and delivered under your change control.

PII masked before the prompt

Personally-identifying data is masked or tokenised before any text reaches a model. Sensitivity never becomes exposure.

Identity & least privilege

Authentication through your Active Directory or Okta; the agent acts only within the entitlements of the operator behind it.

Deterministic execution

Evaluation gates and state machines bound what the system can do; consequential actions require human confirmation and leave an immutable trail.

Improve without exfiltrating

Fine-tuning happens on your data, inside your perimeter. The model compounds; the data stays home.


02 / 02, Compliance roadmap

Building toward SOC 2 and ISO 27001 alignment, with sector-specific controls layered on top.

A security-first briefing maps our architecture to your regime in detail, deployment topology, the controls that apply, and our current posture. We prefer the hard questions early.

Security FAQ

Does our operational data leave our perimeter?+

No. Limen runs domain-adapted models inside your own boundary, your VPC, or fully air-gapped, so operational data is processed locally and nothing crosses the boundary. There is no third-party inference endpoint to subpoena, breach, or quietly re-price. Sovereignty is an architecture, not a contract clause.

What does 'air-gapped' mean here?+

It means a deployment topology with no route to the public internet at all, the models, the control plane and your data run entirely within your isolated network. Model updates are packaged and delivered under your own change control rather than pulled from us. This is built for flag carriers, ministries, defence suppliers and firms holding privileged material, for whom a public-cloud endpoint is a disqualification. See sovereign by design.

How is personally-identifying data protected?+

PII and PHI are masked or tokenised before any text reaches a model, so sensitivity never becomes exposure. Authentication runs through your Active Directory or Okta, and the agent acts only within the entitlements of the operator behind it, least privilege, enforced by design. Every action is logged with the operator and the exact command for a complete audit trail.

How do the models improve without our data leaving?+

Fine-tuning happens on your data, inside your perimeter, on a monthly cadence: the platform ingests its own anonymised telemetry and learns from your operators' corrections. The model compounds while the data stays home. The model you launch with is the weakest one your organisation will ever run.

Is Limen certified to SOC 2, ISO 27001 or GDPR?+

We are early-stage and building toward SOC 2 and ISO 27001 alignment, with sector-specific controls layered on top; we will not overstate our current posture. Because operational data never leaves your perimeter, the GDPR and data-residency story is architectural rather than contractual. A security-first briefing maps our design to your regime in detail, deployment topology, applicable controls, and where we stand today.

What are the deployment requirements?+

Limen deploys into infrastructure you already control, a cloud VPC, private data centre, or a fully isolated air-gapped enclave, with GPU capacity sized to the workflows in scope. We integrate with your existing identity provider and change-management process rather than around them. The exact footprint is scoped during T1 Recon so the requirement matches the workload, not a template.

What happens if the agent takes a wrong action, who is liable?+

The architecture is built so a wrong autonomous action is not a normal failure mode: consequential writes are drafted for human confirmation, gated by evaluation checks, and the controller halts to a person on uncertainty. Liability, indemnities and the exact boundary of autonomy are set explicitly in the commercial agreement, we do not hide behind an as-is disclaimer, and we scope autonomy to what your governance is comfortable owning. See how the controls work.

Who can the agent act as, and how is access controlled?+

The agent inherits the identity and entitlements of the operator using it, authenticated through your own directory, it can never do something that operator is not permitted to do. Role changes and revocations propagate from your identity provider immediately, so access control stays where your security team already manages it. Nothing runs as an unscoped super-user.

Bring your security team to the first call.

See the platform