SECURITY & SOVEREIGNTY
Your data, models, and context. Inside your walls.
zaimler auto-infers live runtime context, entirely inside your perimeter. Zero egress. Governed by your enterprise identity controls
[ 01 · DEPLOYMENT ]
Runs where your data lives
zaimler installs as a self-contained, Kubernetes-native platform inside your VPC on EKS, AKS, or GKE, or fully on-premises, running alongside your data. Updates come in through the zaimler software depot, validated, and nothing about your data goes back out. A managed cloud exists for teams without strict residency requirements. Regulated data almost always runs self-hosted.
Cloud-Native Deployment
Self-contained and Kubernetes-native, deployed alongside your data
Data Privacy by Design
In a self-hosted deployment, no customer data transits zaimler-managed systems
Full Tenant Isolation
Tenant-resident: the whole platform, data and control, lives in your environment
NO EGRESS
Everything stays inside the boundary
Sources are read in place, and you choose what gets indexed. The models run inside the deployment, whichever ones you choose, and nothing calls out to an external model API.
Data is encrypted with AES-256 at rest and TLS in motion, and every internal service talks over Istio mTLS.
Runtime Access Governance
Access is governed at the moment of retrieval. Every request, from a person in the console or an agent over MCP, clears role and attribute checks synced from your identity provider. Workspaces isolate departments, domains, and use cases inside a tenant, each with its own roles and data connections. Every create and update lands in an audit log.
End-to-End Encryption
AES-256 at rest, TLS in motion, Istio mTLS between every internal service
On-Premise AI Models
Self-hosted models, with no external model API calls
Secrets Management
Source credentials encrypted in the zaimler secret store, never exposed in transit, validated at every step
Identity Federation
SSO through Active Directory, LDAP, OIDC, or SAML, with SCIM provisioning
Role-Based Access
RBAC and ABAC, enforced with Keycloak and CEDAR, scoped to tenant or workspace
Audit Trail
Append-only audit log: every record carries the user and its origin, UI, API, or SDK, readable by tenant admins and exportable to CSV
[ 03 · COMPLIANCE & SOVEREIGNTY ]
Sovereign by design, certified by audit
The platform is built to meet GDPR, HIPAA, and 23 NYCRR 500 requirements. Sovereignty is structural: because the deployment is self-contained, a regional deployment keeps the data, the models, and the ontology in that region. The attestation confirms what the architecture already enforces.
SOC 2 Type II, report shared under NDA
ISO 27001; GDPR, HIPAA, and 23 NYCRR 500 requirements
Residency follows the deployment itself
Full detail at trust.zaimler.ai
SOC 2 Type II
Certified
ISO 27001
Certified
GDPR
Certified
HIPAA
Certified
23 NYCRR 500
Certified
FAQ
zaimler is the context layer for production agents. It builds the context AI agents need automatically, from the data an enterprise already has, and keeps it owned by the customer, so agents operate in production: accurate, real-time, complete, and governed. It runs today inside regulated enterprises, where a wrong answer is a mis-paid claim.
Tools like Cortex Analyst rely on hand-written YAML semantic files you maintain yourself. zaimler's ontology is auto-inferred from your data with confidence scores, then validated by your team, in days rather than the quarters a hand-built model takes.
All inputs and outputs are your intellectual property