RedactNode
DEPLOYMENT ROOM/INFRASTRUCTURE BOUNDARIES

Place the Boundary Where Your Trust Lives.

Enterprise AI security is not a desktop installer. It is an enforceable boundary between your internal network and external foundation model providers. Select the architecture your IT team can confidently own.

Organisation-owned runtime boundary
Ephemeral AES-256 session token vaults
Zero-honeypot cryptographic audit evidence
No raw prompts stored in IT review portals
DEPLOYMENT BOUNDARYSOVEREIGN ISOLATION
YOUR ENTERPRISE NETWORK
PORTAL
TOKEN VAULT
AUDIT PROOF
Raw Identifiers Terminated Here
PUBLIC AI PROVIDERMasked Surrogates Only
[ 01 / BOUNDARY OPTIONS ]

Three operating boundaries for enterprise scale

There is no universal one-click download for privacy infrastructure. Start with the operational boundary that satisfies your data protection officer and platform architects.

MANAGED SOVEREIGN

Hosted Safe Zone

Use our managed cloud portal while your security and compliance teams validate prompt tokenization and evaluate regulatory policies.

Instant zero-ops provisioning
Automatic Malaysian regex updates
SOC 2 Type II data protection
Launch Hosted Safe Zone
ENTERPRISE BOUNDARY

Private VPC Deployment

Deploy the portal, Tanda Gateway, in-memory Redis vault, and audit stream directly inside your AWS, Azure, or Google Cloud VPC.

Customer-controlled network boundary
No raw telemetry leaves your cloud
Central GPO/Intune extension sync
Configure Private VPC Build
BNM RMiT ALIGNED

Air-Gapped Hardware Enclave

For banking, defense, and healthcare environments with strict statutory air-gap requirements and zero outbound internet connectivity.

Hardened bare-metal appliance image
Local offline inference integration
Zero external DNS dependencies
Request Enclave Architecture Pack
[ 02 / ENCLAVE STACK ]

A lean control plane with unambiguous boundaries

The private build is designed for operational clarity: one internal web portal, one reverse proxy gateway, an in-memory token vault, and a cryptographically sealed audit stream that records evidence without archiving raw prompt text.

Safe Zone Web Portal

Internal chat surface for employees requiring transparent PII tokenization

Tanda Gateway Reverse Proxy

Policy enforcement: Inspect -> Mask -> LLM Dispatch -> Re-hydrate

Tamper-Evident Audit Stream

Immutable cryptographic SHA-256 logs recording compliance rule events

In-Memory Redis Vault + PostgresZero Cleartext Egress
[ 03 / DEPLOYMENT CALCULATOR ]

Where should RedactNode run in your network?

Choose the operational model that fits your enterprise governance mandates. You can transition from hosted pilot to self-hosted VPC cluster seamlessly.

RECOMMENDED OPERATING PATTERN

Your Cloud Infrastructure Boundary

Run the protected portal, Tanda Gateway, in-memory token vault, and audit stream inside your organisation's AWS, Azure, or GCP tenancy.

Kubernetes Helm charts, Redis vault, Postgres, sovereign encryption keys
[ 04 / ENTERPRISE PACK ]

Complete documentation for security reviews

Private deployments begin with clear architectural documentation, not an unvetted mystery binary. We provide the material your platform, security, and data governance teams require for sign-off.

Detailed data-flow & network ingress diagrams
Environment variable configuration reference
In-memory Redis vault sizing & TTL guidance
Chromium GPO / Microsoft Intune extension pilot guide
Bank Negara Malaysia (BNM) RMiT cloud matrix
Tamper-evident SHA-256 audit stream specifications
PILOT READY/MANAGED ROLLOUT

Prove the workflow before you move the walls

Start with the hosted Safe Zone, conduct a department pilot, and migrate the boundary when data residency and network ownership requirements are formally established.