SECURITY & SOVEREIGNTY

Your data, models, and context. Inside your walls.

zaimler auto-infers live runtime context, entirely inside your perimeter. Zero egress. Governed by your enterprise identity controls

[ 01 · DEPLOYMENT ]

Runs where your data lives

zaimler installs as a self-contained, Kubernetes-native platform inside your VPC on EKS, AKS, or GKE, or fully on-premises, running alongside your data. Updates come in through the zaimler software depot, validated, and nothing about your data goes back out. A managed cloud exists for teams without strict residency requirements. Regulated data almost always runs self-hosted.

Cloud-Native Deployment
1

Cloud-Native Deployment

Self-contained and Kubernetes-native, deployed alongside your data

Data Privacy by Design
2

Data Privacy by Design

In a self-hosted deployment, no customer data transits zaimler-managed systems

Full Tenant Isolation
3

Full Tenant Isolation

Tenant-resident: the whole platform, data and control, lives in your environment

NO EGRESS

Everything stays inside the boundary

Sources are read in place, and you choose what gets indexed. The models run inside the deployment, whichever ones you choose, and nothing calls out to an external model API.

Runtime Access Governance

Data is encrypted with AES-256 at rest and TLS in motion, and every internal service talks over Istio mTLS.

Runtime Access Governance

Access is governed at the moment of retrieval. Every request, from a person in the console or an agent over MCP, clears role and attribute checks synced from your identity provider. Workspaces isolate departments, domains, and use cases inside a tenant, each with its own roles and data connections. Every create and update lands in an audit log.

End-to-End Encryption

AES-256 at rest, TLS in motion, Istio mTLS between every internal service

On-Premise AI Models

Self-hosted models, with no external model API calls

Secrets Management

Source credentials encrypted in the zaimler secret store, never exposed in transit, validated at every step

Identity Federation

SSO through Active Directory, LDAP, OIDC, or SAML, with SCIM provisioning

Role-Based Access

RBAC and ABAC, enforced with Keycloak and CEDAR, scoped to tenant or workspace

Audit Trail

Append-only audit log: every record carries the user and its origin, UI, API, or SDK, readable by tenant admins and exportable to CSV

[ 03 · COMPLIANCE & SOVEREIGNTY ]

Sovereign by design, certified by audit

The platform is built to meet GDPR, HIPAA, and 23 NYCRR 500 requirements. Sovereignty is structural: because the deployment is self-contained, a regional deployment keeps the data, the models, and the ontology in that region. The attestation confirms what the architecture already enforces.

  • SOC 2 Type II, report shared under NDA

  • ISO 27001; GDPR, HIPAA, and 23 NYCRR 500 requirements

  • Residency follows the deployment itself

  • Full detail at trust.zaimler.ai

SOC 2 Type II

SOC 2 Type II

Certified

ISO 27001

ISO 27001

Certified

GDPR

GDPR

Certified

HIPAA

HIPAA

Certified

23 NYCRR 500

23 NYCRR 500

Certified

FAQ

zaimler is the context layer for production agents. It builds the context AI agents need automatically, from the data an enterprise already has, and keeps it owned by the customer, so agents operate in production: accurate, real-time, complete, and governed. It runs today inside regulated enterprises, where a wrong answer is a mis-paid claim.

Tools like Cortex Analyst rely on hand-written YAML semantic files you maintain yourself. zaimler's ontology is auto-inferred from your data with confidence scores, then validated by your team, in days rather than the quarters a hand-built model takes.

All inputs and outputs are your intellectual property

Your data, your IP. Always. Everything zaimler learns about your business belongs to you. In a self-hosted deployment, it never leaves your environment, and it’s never used to train models.