Security

Our assurance isn't a certificate. It's the design.

Zirah is early, and we won't pretend otherwise — we don't hold certifications yet. What we have is an architecture where the worst outcome is designed out: your data stays in your environment, sensitive work runs in sealed compute, and every reveal is on the record.

Your data stays where it is

Zirah is self-hosted, in your environment. You hold the keys. We have no access to your data, and nothing is sent to a shared service to be processed. The protection isn't a promise about our conduct — there's nothing on our side to trust.

The bad outcome is designed out

These are properties of how Zirah is built, demonstrable today — not a program we're asking you to take on faith.

Confidential compute

Attested enclave. Attestation you can confirm yourself.

Fail-closed by default

Breaks stop, they don't leak.

No self-approval

Reveals need a second person.

Redacted before it leaves

Masked before any external model, holds through streaming.

On the record

Every block, exception and reveal logged, watermarked, SIEM-exported. Queues if SIEM is down.

Scoped to identity

Retrieval trimmed to what each person may see, from your IdP.

Where our job ends and yours begins

Zirah enforces
  • Redaction
  • Policy
  • Segregation of duties
  • Audit logging
  • Enclave attestation
  • Fail-closed behavior
You own
  • Key custody
    You keep control; you also carry the recovery burden.
  • Your identity provider and its group hygiene
    Scope is only as tight as your IdP groups.
  • Deployment posture choices
    Tighter isolation costs more; looser costs less blast radius protection.

How we think about security

Assurances, not guarantees

We describe what the system does and its limits, and don't dress an assurance up as a warranty.

Honest mechanism

Every claim maps to something the system does. Roadmap items are labelled roadmap.

Every block has a way out

Controls that only say no get worked around. Ours offer an exception path that stays on the record.

Where we are

Honestly, early.

We're waiting on our first customers, and we're not going to hide that. We don't hold SOC 2 or ISO 27001 today. We intend to pursue them — and we'd rather build that program alongside design partners who help shape it than claim a badge we haven't earned. Until then, our case rests on the architecture above, which you're welcome to examine yourself.

Found something?

If you've found a security issue, tell us at security@zirah.ai. We publish a security.txt, and we'll work the report through with you.

Read the architecture yourself

The deep detail — the enclave model, corpus protection modes, the policy engine, the attestation flow — lives in a technical and security brief we share under NDA. Ask and we'll send it.

Ready to shape what confidential AI looks like?