No public route
Precepta runs in your cloud account or data centre with no route to the public internet.
Security and sovereignty
Not the interface with the reasoning elsewhere — all of it. Models, gateway, policy, audit and the record itself, inside your own network, over whichever models you choose to run.
| Question | Answer |
|---|---|
| Does our data reach you? | No. There is no environment of ours for it to sit in — how the boundary is built |
| Where does inference happen? | In your boundary, on models you run — or a hosted provider your platform owner has explicitly approved |
| What do you hold about us? | Nothing. No prompts, completions, embeddings or audit records |
| Is there telemetry? | None. No phone-home, no usage reporting, no licence check that calls out |
| Can we prove what happened? | Yes — every stage of a request is recorded, with integrity chained |
| Which models can we use? | Any. Open-weight in boundary, or an approved hosted provider — never locked to ours |
| Who are your sub-processors? | None, because nothing flows to us — the full list |
| How do we report a vulnerability? | hello@liminalabs.in — disclosure policy |
How the boundary is built
The boundary is a property of where the software sits, not a setting inside it. That is the whole argument, and it is structural rather than a promise.
Precepta runs in your cloud account or data centre with no route to the public internet.
Models run on your hardware. There is no route to an external host unless your platform owner has approved that exact one.
No phone-home and no usage reporting, so there is no path over which your data could reach us.
A live egress probe tests the boundary at boot and on demand, and a signed attestation records the posture.
What a request leaves behind
Every request is recorded at each stage it passes through, with the decision taken and the reason for it. Integrity is chained, so a record cannot be altered after the event without the alteration being evident.
That is what makes an answer possible when compliance asks what happened to a specific request, months later.
Recorded at every stage
Firewall → Sensitivity → Policy → Smart Route → Cache → Inference → Audit
Redaction happens before a model sees the request; the output is scanned for leaks on the way back. Both are recorded.
Model freedom
Precepta is a control plane, not a model vendor. Run open-weight models in your own boundary, or reach a hosted provider where your platform owner has approved that exact host. Both paths take the same governed pipeline.
This is the point of putting the boundary outside the model. A better one arrives every few months and you should be able to take it without rebuilding anything. What stays is the rules, the record and the work you have already agreed — the part you actually own.
How releases are built
Dependencies are scanned and releases are signed. The identical artifact runs in an evaluation, in a self-hosted deployment and on-premises — there is no separate build with different behaviour.
Sixty to ninety minutes on a live deployment, where they pick what to try — including the exfiltration attempt. We do not get to set the questions, and nothing here is behind a form.