ModelRig / security
Security posture, stated plainly.
All hosted data lives on SOC 2 Type II–audited infrastructure, encrypted in transit and at rest, row-scoped to your organization by the database itself — and everything we hold, you can see, export, and delete.
Four lanes. You pick per route.
Self-host — the open lane
Your infrastructure end to end. There is no ModelRig data plane to audit.
Pure router (hosted, capture off)
Nothing retained. zero_retention is a routing predicate, not a meeting.
Metadata & hashes
Telemetry rows, costs, grades, and content hashes; the bytes never reach us.
Bring your own bucket
Content in your store under your controls; lineage and scoring in ours.
Managed custody — where we hold the bytes — is early access, and is the lane our own SOC 2 attestation exists for. What we keep, and what you get for it
How data moves
You can see exactly what we hold, and take it back.
The request-side lane
Custody governs what ModelRig stores; masking governs what leaves for the provider. A per-route policy tokenizes detected spans before dispatch, rehydrates the answer after, and records a counts-only receipt on every step — deterministic detectors plus your own dictionary and field rules.
And the policy carries proof: a masked-vs-unmasked bake-off on your replayed traffic reports the value-accuracy Δ with a confidence interval, so you promote a mask only once the evidence shows it didn't change the answer — a pull request, never a silent switch.
Provenance-first assembly
Every content segment ModelRig assembles carries its source and trust tier. The system slot holds trusted segments only; untrusted content — web-search results, third-party variables, relayed proxy turns — is isolated as data in a spotlighted, JSON-encoded user-slot block, so it is delivered as data, not instructions. The assembler decides slot placement structurally, before any detector runs — a deterministic control, not a probabilistic one.
On top of that isolation, a route can screen: a deterministic pattern pack flags known injection shapes, an optional in-process classifier adds a risk signal, and a flagged turn can be quarantined — dispatched with tool calls barred, so the untrusted turn cannot actuate a tool through ModelRig. Every screened step records a counts-only receipt: findings by type and source, quarantined tool-call counts, canary leaks — never a matched value.
Deterministic assembly, a pattern pack, and an optional in-process classifier. They isolate untrusted content and flag known injection shapes; they do not prevent injection — no detector can. We publish the measured false-positive rate instead of a guarantee.
PII/PHI Safe Harbor coverage
On top of injection screening, a route can turn on deterministic HIPAA Safe Harbor identifier detectors — dates, ages over eighty-nine, fax and phone, email, SSN and MRN, account and license numbers, VINs and device ids, URLs and IP addresses — beside the free-text names and street addresses a customer-run de-id sidecar handles. The sidecar is your own container; ModelRig ships the adapter and the contract, never a bundled model, and the content it sees never returns to a receipt — only per-type counts do.
We publish a per-identifier coverage table: for each of the eighteen HIPAA Safe Harbor classes it says whether ModelRig catches it deterministically in-process, needs the sidecar, or leaves it out of scope. A route classified for PHI refuses to load unless it masks its content and either retains nothing or runs the sidecar.
PII/PHI screening with published detector coverage; recall is measured on synthetic PHI, not assumed. We publish a coverage table and measured false-positive rates, not a compliance guarantee — no detector removes every identifier on its own.
See the measured false-positive rate of our built-in detectors →
Evidence, not adjectives
Access rules are enforced by the database — deny-all first, membership-scoped policies — and the exact policy set is asserted in CI: a drifted policy fails the build, not the audit. Live probes with anonymous and forged credentials run against the deployed service, with transcripts. Every schema migration ships with an application transcript. Export is a console action, and removing stored content is a single owner-authorized API call — neither is a support ticket.
Where certification stands
Our own SOC 2 Type II attestation is on the roadmap — its clock starts when managed content custody reaches general availability. Until then, pick the lane where we never hold the sensitive bytes; the posture above is the product, not the paperwork.
A security-questionnaire response pack — including the named subprocessor list — is available on request.