cstm.ai · Custom AI hardware, software & developmentVendor-neutral · Quote onlyBuilt to spec
CSTM-SW · GOVcstmAI™ · Software

AI governance software built into every request.

cstmAI™ Govern decides who may use which models and data, masks sensitive fields before they reach a model when policy says so, and keeps an audit record of every request and response.

Fig. 01 · Machine shop interior, Paterson, NJca. 1890

Security and compliance reviews ask the same questions: who can use it, what data can it see, what did it say, and can you prove it. Govern answers them with configuration and logs, rather than a policy document no system enforces.

It supports HIPAA, SOC 2 and GDPR programs by providing the technical controls those programs ask for: access control, audit trails, retention settings and redaction. Compliance belongs to your whole program, not to a product, so we work with your security team to map each control.

At a glanceCSTM-SW · GOV
AccessRole and group permissions per model, data source and agent
AuditUser, model, sources, request and response for every call
RedactionConfigurable detection and masking of sensitive fields
RetentionLog retention set by your policy
ProgramsSupports HIPAA, SOC 2 and GDPR programs
Controls

The answers your security review will ask for.

01CSTM-SW

Permissions

Which teams may use which models, data sources and agents.

02CSTM-SW

Audit trail

A searchable record of every request, answer and source.

03CSTM-SW

Redaction

Sensitive values such as account or ID numbers masked before the model sees them.

04CSTM-SW

Usage policy

Rules for which data classes may go to which models and tools.

Radial drill press and milling machines with a rack of long steel rods in a dim machine shop bay
Reel 02 · Milling and boring area, Paterson, NJ1994
How it's delivered

Four steps, each one signed off.

01

Map requirements

Your control framework, translated into settings.

02

Configure

Roles, data classes, redaction rules and retention.

03

Test

Attempt the things policy forbids and confirm they fail.

04

Document

A control map your auditors can follow.

FAQ

Questions we hear first.

Is cstmAI certified for HIPAA or SOC 2?

No product makes an organization compliant by itself. cstmAI supports HIPAA, SOC 2 and GDPR programs with access control, audit logging, retention and redaction, and we document how each control maps to your requirements.

Can the logs go to our SIEM?

Govern is designed to export its audit records to the tools your security team already uses. We confirm the integration with your specific SIEM in discovery.

How does redaction work?

Detectors find the sensitive fields you configure in prompts and documents and mask them before the model sees them, where policy requires. We tune and test the detectors on samples of your own data.

Get a quote

Spec your system.

Tell us the models you want to run, how many people will use them and where the hardware should live. An engineer replies with a first configuration and the questions that decide the quote.

Form CSTM-Q · Quote only