Isolation, Access Tiers,
and Audit Trail
Security is the architecture, not a feature. Every layer is designed with the assumption that data must be protected from unauthorised access — even from the AI system itself.
Local Guardian Agent
An independent AI agent at the boundary of every data flow. It classifies sensitivity in real-time, decides what context may leave the local environment, and has veto authority over outbound transmission — regardless of what other agents request.
Vault-Encrypted Document Storage
All documents are encrypted at rest using AES-256 within a secure vault. Decryption occurs only server-side after authorisation verification. Documents are classified upon ingestion and access is governed by clearance policies.
Complete Audit Trail
Every interaction with any AI model — local or cloud — is logged with full provenance. What was sent, which model processed it, what was returned, and who authorised it. Tamper-resistant storage creates a reconstructible record of all AI operations.
Access Tiers
AEXOS enforces role-based access across a clear hierarchy. Executives see the full decision pipeline. Delegates operate within assigned boundaries. Delivery staff access only what the engagement requires. No lateral movement between tiers.
Security Principles
Least Privilege
Every agent and model receives only the minimum data required for its specific task. No system component has blanket access to all organisational data.
Defence in Depth
Multiple independent security layers — classification, encryption, access control, audit logging, and the Local Guardian — ensure no single point of failure can compromise data.
Reconstructible Record
Any decision pathway can be reconstructed at any time — which models were used, what data was accessed, what was recommended, and who authorised the outcome.
Optional On-Premise Operation via AsymiLink AI
For organisations requiring complete data sovereignty, AEXOS can run the sensitive work on client-owned infrastructure via AsymiLink AI. No data — including model prompts, responses, or metadata — is transmitted outside the premises. Suitable for ITAR, defence, and classified environments where cloud exposure is prohibited.
Security by architecture
Organisations handling ITAR, PHI, CUI, and classified data require AI systems that enforce security at the infrastructure level.