Skip to content
FortiqAI Technologies LLP
Security

Security isn't a feature. It's the foundation.

FortiqAI is built for organizations that need AI capability without exposing sensitive data to public platforms. No cloud. No risk. Total control.

01

Where your data actually goes.

Every organization that hands FortiqAI its internal knowledge asks this first. This page answers it in full, so your security and compliance teams don't have to take our word for it.

Your walls

Your Knowledge, Your Walls

Runs entirely inside infrastructure you control — on-premises, private cloud, or fully offline in an air-gapped environment. Nothing is copied to a shared multi-tenant cloud.

No exposure

No Public Data Exposure

Works offline, on your machine, and never phones home. No telemetry, no background sync, no vendor lock-in, and nothing used to train a public model.

Access control

Role-Based Access

RBAC lets you decide which users and teams can query which document collections — down to the individual matter or project.

Verify

Source-Grounded Answers

Every answer traces back to the original document. No black-box responses — your team can always open the source and verify it.

Observe

Auditability

Usage logs show who asked what, when, and which documents were accessed — so you can answer your own compliance questions about AI usage.

By design

Responsible by Design

Built to support human decision-making, not replace it. Sensitive workflows require review, context, and accountability — always.

02

What an attacker who reaches the server can, and cannot, do.

Most security reviews start here, so we'll start here too.

Documents and vector embeddings are stored on your infrastructure, encrypted at rest. Credentials for administrative access are separate from the credentials your users authenticate with, and neither is stored in plaintext.

Traffic between your users and the application is encrypted in transit. Because the deployment has no outbound path to a public AI service, there is no external endpoint for a compromised credential to exfiltrate data to beyond your own network boundary — the blast radius of a breach is scoped to your environment, not shared with other customers on shared infrastructure, because there isn't any.

03

What happens when you decommission.

Removing a document from the index removes it from retrieval immediately. On full decommission, indexed content, embeddings, and cached data are deleted from the deployment; nothing is retained on infrastructure we control, because none of your document data ever touches infrastructure we control. Audit logs are retained on your own systems for as long as your internal policy requires — that retention period is yours to set, not ours.

04

What We Don't Claim

Where our certifications currently stand.

FortiqAI does not currently hold SOC 2 or ISO 27001 certification. We say so plainly rather than implying otherwise, and we will tell you where that stands when you ask. What we will do is walk your security team through the deployment architecture in detail and answer their questionnaire directly. See also our Compliance & Regulatory Fit page for how a private deployment maps to DPDP, GxP, RBI, and GDPR obligations.

Security Architecture

Bring AI into your organization without sending data out.

We'll walk your security and compliance team through exactly how FortiqAI is deployed, governed, and audited inside your environment.

Request Overview
On your infrastructure · Air-gap capable · Role-based access · Every answer cited · Full audit log