Permissions
Which teams may use which models, data sources and agents.
Tell us the models and the users. We return a configuration sheet and a quote.
Spec a system →Model serving, access control and monitoring on hardware you own.
See the platform →
Thirty minutes with an engineer: your workflow, your data, and whether custom AI fits.
Book a scoping call →
cstmAI™ Govern decides who may use which models and data, masks sensitive fields before they reach a model when policy says so, and keeps an audit record of every request and response.
Security and compliance reviews ask the same questions: who can use it, what data can it see, what did it say, and can you prove it. Govern answers them with configuration and logs, rather than a policy document no system enforces.
It supports HIPAA, SOC 2 and GDPR programs by providing the technical controls those programs ask for: access control, audit trails, retention settings and redaction. Compliance belongs to your whole program, not to a product, so we work with your security team to map each control.
| Access | Role and group permissions per model, data source and agent |
|---|---|
| Audit | User, model, sources, request and response for every call |
| Redaction | Configurable detection and masking of sensitive fields |
| Retention | Log retention set by your policy |
| Programs | Supports HIPAA, SOC 2 and GDPR programs |
Every module runs on the same platform and hardware, under the same governance.
Which teams may use which models, data sources and agents.
A searchable record of every request, answer and source.
Sensitive values such as account or ID numbers masked before the model sees them.
Rules for which data classes may go to which models and tools.

Your control framework, translated into settings.
Roles, data classes, redaction rules and retention.
Attempt the things policy forbids and confirm they fail.
A control map your auditors can follow.
No product makes an organization compliant by itself. cstmAI supports HIPAA, SOC 2 and GDPR programs with access control, audit logging, retention and redaction, and we document how each control maps to your requirements.
Govern is designed to export its audit records to the tools your security team already uses. We confirm the integration with your specific SIEM in discovery.
Detectors find the sensitive fields you configure in prompts and documents and mask them before the model sees them, where policy requires. We tune and test the detectors on samples of your own data.
Tell us the models you want to run, how many people will use them and where the hardware should live. An engineer replies with a first configuration and the questions that decide the quote.