Runs in your own cloud
Designed to run entirely inside your environment, so your data stays in your cloud. With in-tenant inference, the models run there too. No copy of your data sits on our infrastructure.
Consolidate is architected so your research data stays yours: permission-aware, default-deny, and designed to run entirely inside your own cloud. Consolidate is early / pre-launch, so this is a straight account of how it's built, how it deploys, and what's still on the roadmap.
Properties of how the product is built and deployed, not marketing.
Designed to run entirely inside your environment, so your data stays in your cloud. With in-tenant inference, the models run there too. No copy of your data sits on our infrastructure.
Access is enforced per-fact against your source systems' own permissions, applied before the model reads anything, and defaulting to deny.
Access mirrors each connected system, down to channel membership and sensitivity class, rather than a coarse, all-or-nothing role.
Read-only connectors. We never modify your systems, and your data is never used to train a model.
Each claim traces back to the exact record it came from, so every answer is verifiable against its sources.
When the evidence isn't there, Consolidate says so. It won't fabricate. An unverified answer is worse than none.
In the own-cloud deployment with in-tenant inference, no third-party model provider receives your data. (Current previews use an external model provider, one of the first things the own-cloud deployment removes.)
TLS in transit; stored source credentials sealed with AES-256. Research data at rest is protected by your own cloud's disk encryption.
Where each control stands. Available = real in the product today. By design = an architectural property, not yet deployed for a customer. Planned = on the roadmap, not built. We mark nothing higher than it is.
| Control | Status |
|---|---|
| Permission-aware, default-deny access | Available |
| Native source-permission fidelity + sensitivity classes | Available |
| Read-only connectors · no training on your data | Available |
| Source-cited, verifiable answers | Available |
| Encryption in transit (TLS) · AES-256 stored credentials | Available |
| Single-tenant, own-cloud deployment model | By design |
| In-tenant inference (removes the model sub-processor) | Planned |
| SSO / SAML & SCIM provisioning | Planned |
| Immutable, exportable audit logs | Planned |
| Customer-managed keys (BYOK / KMS) | Planned |
| 21 CFR Part 11 electronic signatures | Planned |
| SOC 2 Type II | Planned |
| ISO 27001 | Planned |
| Third-party penetration test | Planned |
By design, deploying in your own cloud answers much of a typical vendor security review through architecture: your data stays in your environment, so there's no shared tenant to breach and, once in-tenant inference is enabled, effectively no data sub-processors to vet.
We're happy to walk your security team through the architecture and complete your questionnaire.
Talk to us → ← Back to consolidate.bio