Skip to content
Limina Labs
Contact us
Intent Studio Precepta Cerebrio Sovereign AI Pricing Security Company Contact us

Security and sovereignty

The whole stack runs on your infrastructure.

Not the interface with the reasoning elsewhere — all of it. Models, gateway, policy, audit and the record itself, inside your own network, over whichever models you choose to run.

Short answers to the questions security teams ask
QuestionAnswer
Does our data reach you?No. There is no environment of ours for it to sit in — how the boundary is built
Where does inference happen?In your boundary, on models you run — or a hosted provider your platform owner has explicitly approved
What do you hold about us?Nothing. No prompts, completions, embeddings or audit records
Is there telemetry?None. No phone-home, no usage reporting, no licence check that calls out
Can we prove what happened?Yes — every stage of a request is recorded, with integrity chained
Which models can we use?Any. Open-weight in boundary, or an approved hosted provider — never locked to ours
Who are your sub-processors?None, because nothing flows to us — the full list
How do we report a vulnerability?hello@liminalabs.indisclosure policy

How the boundary is built

We cannot lose data we never receive.

The boundary is a property of where the software sits, not a setting inside it. That is the whole argument, and it is structural rather than a promise.

Placement

No public route

Precepta runs in your cloud account or data centre with no route to the public internet.

Inference

In-boundary by default

Models run on your hardware. There is no route to an external host unless your platform owner has approved that exact one.

Telemetry

No channel back to us

No phone-home and no usage reporting, so there is no path over which your data could reach us.

Proof

Probed, not asserted

A live egress probe tests the boundary at boot and on demand, and a signed attestation records the posture.

Demonstrated on your network, not on this page. The attestation is the part we most want you to distrust on principle, so it is shown during an evaluation inside your own infrastructure, with your team choosing the tests — including the exfiltration attempt.

What a request leaves behind

The whole governed journey, replayable.

Every request is recorded at each stage it passes through, with the decision taken and the reason for it. Integrity is chained, so a record cannot be altered after the event without the alteration being evident.

That is what makes an answer possible when compliance asks what happened to a specific request, months later.

Recorded at every stage

Firewall → Sensitivity → Policy → Smart Route → Cache → Inference → Audit

Redaction happens before a model sees the request; the output is scanned for leaks on the way back. Both are recorded.


Model freedom

Any model, and never locked to ours.

Precepta is a control plane, not a model vendor. Run open-weight models in your own boundary, or reach a hosted provider where your platform owner has approved that exact host. Both paths take the same governed pipeline.

This is the point of putting the boundary outside the model. A better one arrives every few months and you should be able to take it without rebuilding anything. What stays is the rules, the record and the work you have already agreed — the part you actually own.

How releases are built

The same artifact you evaluate is the one you run.

Dependencies are scanned and releases are signed. The identical artifact runs in an evaluation, in a self-hosted deployment and on-premises — there is no separate build with different behaviour.


Let your security team choose the tests.

Sixty to ninety minutes on a live deployment, where they pick what to try — including the exfiltration attempt. We do not get to set the questions, and nothing here is behind a form.