Security
Your data stays yours.
Sediment runs on a machine dedicated to your company and never sends your data to an outside model provider.
Where it runs
Dedicated machine
- Where it runs
- a machine we operate, only for you
- Keys and logs
- logs exported to you
- Paper
- NDA, DPA, deletion certificate
Your cloud account
- Where it runs
- inside your AWS, Azure, or Google Cloud
- Keys and logs
- yours
- Paper
- NDA, access agreement
What's true today
No outside calls
Sediment 1 runs entirely on your dedicated machine. It makes zero outbound calls to OpenAI, Anthropic, or anyone else. Block all outbound traffic at your firewall and it still runs.
One company per machine
Your records, and everything built from them, live only in your deployment and are deleted with it. Nothing is pooled or reused for another company.
An audit log you can read
Every question, answer, source, and user is written to an append-only log you can export at any time. The application never edits or deletes it.
Access by person
Each user sees only what they are scoped to. Someone on one project can't read another.
Files stay put
Files attached to a conversation stay in that conversation, are never indexed, and can be deleted at any time.
Encrypted at rest
Your data is encrypted at rest on the machine's disks.
What we sign
- Your NDA or ours.
- A data processing agreement.
- A no-reuse clause: your data and anything built from it is used for you only.
- Outputs belong to you.
- When we part ways, a deletion certificate, with the audit export as proof of what was accessed.