Tileward / Security
Security

The strongest control we offer is not receiving your data.

Choose the data boundary first: Tileward can run as a hosted service, inside your VPC, or fully air-gapped. In the last two modes, the inference data path stays on infrastructure you control.

Architecture

Pick your exposure.

These are materially different answers to “who can reach this data.” See the complete request path, then choose the boundary that fits it.

Hosted API
Minutes
  • We hold prompts, context and audit records
  • Everything on this page applies
  • Zero infrastructure for you
Your VPC
Days
  • One node, one GPU
  • Content, context and audit stay in your account
  • Your controls, your network boundary
On-prem, air-gapped
Weeks
  • No network path out
  • Flat licence, no metering
  • Audit records retained locally

If your threat model does not permit prompts leaving your network, choose air-gapped.

Governance as a control

A refusal that happens before the model runs.

This is the part of the product that behaves like a security control rather than a feature. More on the governance page.

Nothing off-policy is generated

A locked topic is classified and declined before inference (roughly 14 tokens to decide, and no completion written).

Policy travels with the credential

Rules are bound to the API key, not to a system prompt. A caller cannot drop the policy by changing the prompt, and a leaked key carries only the permissions attached to that key.

Every decision is recorded

Allow and refuse alike: time, tenant and seat, the tile matched, the policy version in force, the verdict, how it matched, and whether the model was invoked. Exportable as CSV or JSON on every plan; webhook and SIEM export are Enterprise.

Matching is by topic, not by keyword

A reworded request in the same vocabulary lands on the same topic. Wording that avoids the topic's vocabulary altogether can still pass, so the match follows the vocabulary rather than the concept.

Audit retention, by plan

PlanAudit windowExport
Explore (free)7 daysCSV, JSON
Build30 daysCSV, JSON
Pro30 daysCSV, JSON
Team1 yearCSV, JSON
Enterprise, self-hostedLocal, your policyCSV, JSON, webhook, SIEM

If you need records kept for longer than a year, that is the self-hosted route, where retention is yours to set.

Certifications

SOC 2 Type II and ISO 27001 are in progress.

SOC 2 Type II, in progress, monitored by Comp AI

SOC 2 Type II

In progress. Monitored by Comp AI.

ISO 27001, in progress

ISO 27001

In progress.

Reporting

If you find something.

Send it to hello@tileward.com and it will reach an engineer. Please give us a chance to fix it before publishing.