The strongest control we offer is not receiving your data.
Most vendor security pages describe how well a company protects data it holds. The more useful thing about Tileward is that it compresses a 35B model to 24.5 GB so you can run it on hardware you own — which means the option of never sending it to us at all is a real one, not a roadmap item.
Pick your exposure.
The three deployment modes are not packaging tiers with the same risk profile. They are materially different answers to "who can reach this data", and the choice is yours.
- We hold prompts, context and audit records
- Everything on this page applies
- Zero infrastructure for you
- One node, one GPU
- Content, context and audit stay in your account
- Your controls, your network boundary
- No network path out
- Flat licence, no metering
- Audit records retained locally
If your threat model does not permit prompts leaving your network, take the third column. Nothing else on this page has to be true for that to work.
A refusal that happens before the model runs.
This is the part of the product that behaves like a security control rather than a feature, so it belongs on this page and not only on the governance one.
Nothing off-policy is generated
A locked topic is classified and declined before inference — roughly 14 tokens to decide, and no completion written. There is no off-policy output to leak, redact or explain, because none was produced.
Policy travels with the credential
Rules are bound to the API key, not to a system prompt. A caller cannot drop the policy by changing the prompt, and a leaked key carries only the permissions attached to that key.
Every decision is recorded
Allow and refuse alike: time, tenant and seat, the tile matched, the policy version in force, the verdict, how it matched, and whether the model was invoked. Exportable as CSV or JSON on every plan; webhook and SIEM export are Enterprise.
Matching survives rephrasing
Classification is semantic, not keyword, so a reworded request lands on the same tile. That is a property we measure rather than assert — see the number below.
Audit retention, by plan
| Plan | Audit window | Export |
|---|---|---|
| Explore (free) | 7 days | CSV, JSON |
| Build | 30 days | CSV, JSON |
| Pro | 30 days | CSV, JSON |
| Team | 1 year | CSV, JSON |
| Enterprise, self-hosted | Local, your policy | CSV, JSON, webhook, SIEM |
If you need records kept for longer than a year, that is the self-hosted route, where retention is yours to set. Webhook and SIEM export are Enterprise only; every other plan exports CSV and JSON.
We hold no certifications, and we will not imply we do.
There is no SOC 2 report, no ISO 27001 certificate, and no HIPAA attestation to hand you. If a page, a deck or a sales conversation suggests otherwise, that is an error and we want to know about it.
Two more limits, both already stated on the governance page and repeated here because a security reader should meet them early rather than late:
The guard is measured, not perfect
Across the governance roster — the 63 regulated topics, which deliberately sit closest together, plus a catch-all for anything outside them — it picks the right one 94.8% of the time. That is a 64-way choice, not a yes/no. We publish that number because a control you cannot quantify is not a control — and for the same reason we publish the one that does not flatter us: a lock over-fires on roughly 1 in 7 unrelated queries, measured on our own benign set. That is a false lock, an over-refusal rather than a leak. The scope and the measurement are under reliability on the governance page.
The knowledge is still in the weights
A lock is a gate at the door, not an erasure. Removing a concept from trained weights is an unsolved problem. Treat a locked tile as a policy control against ordinary use, not as a defence against a determined adversary with model access.
If you find something.
Send it to hello@tileward.com and it will reach an engineer. Please give us a chance to fix it before publishing.