Skip to content
Ilayer

Security and access

Where your data goes, and who can reach it

We work inside your systems under your access controls, in your repositories, under your license. This page is what we can tell you before an NDA.

The work happens inside your systems. One access path crosses the boundary, and you can close it.
01

The access model

The work happens in your systems, not in ours

There is no Ilayer environment your records get copied into. We build in your accounts, your repositories and your systems, under access you grant and can withdraw. Which systems and which accounts is written into the scoping document, before the price is agreed.

  • Access is granted by you, scoped by you, and withdrawn by you.
  • Code lands in your repositories from the first commit, under your license.
A heavy dark bulkhead panel seen straight on, with one circular port bolted into its centre, a machined collar around the opening and violet light filling the glass behind it.
One port, opened by you and closable by you.
What the scoping document contains
02

Keeping clients' data apart

One client's records in another client's answer

When one system answers for several clients, this is the failure that matters most. The answer reads perfectly well and nobody notices. So it is a check that runs on every release, not a promise in a design document.

One client's records on each side, and one boundary between them. Nothing crosses it.
A sealed hexagonal vessel of dark violet glass with machined caps top and bottom, a bright crystalline core blazing at its center, light tracing the seams between its panels.
One client's records sealed inside their own boundary. The zero below is what that seal measured. Illustration, not a screenshot.
0One client's data in another's answersNo case of one client's data reaching another client's answer. Tested at every release, in both of the places the system stores its search index.One live system we built and still operate, measured by its own test gate. A leak test covers the client pairs somebody wrote a test for: a floor, not proof a leak is impossible.

Read the number as one system's record, not an average across ours. A leak test is only as wide as the client pairs written into it.

The five checks in the gate
03

What is retained

Everything the system stores stays where your data already is

A system built to run inside your environment keeps its index, its logs and its test cases there too. We are not running a store of your records on the side. In this delivery model there is nowhere for it to live. Anything that must cross that boundary is named in the scoping document first.

Dark shelves of unlabeled archive canisters receding into shadow. On the middle shelf one open reel sits in a pool of violet light from a small inspection lamp clipped above it.

What we cannot state as fixed policy: a retention window in days. Retention on a system in your accounts is set by your accounts.

04

Model providers

Which model providers touch your records

The models are the ones you already pay for. Which providers a design calls is a scoping decision made with you. On the system this site's numbers come from: Claude on AWS Bedrock, OpenAI for the search index, and Voyage to re-rank the results. One system's design, published so you can check it.

Three separate dark cylinders standing apart in a row, each with a violet-lit window in its face, and three thin threads of light running down from them into one small clear glass junction block in front.
Separate providers, one junction, each one named.

What a provider does with what you send it is governed by your contract with them. We can say what leaves your boundary, not what their terms allow.

05

What we do not have

No SOC 2, no ISO certificate, no penetration test report

We hold none of those. This is the page whose job is answering the question, so we will not imply otherwise. If a certificate is a hard requirement in your procurement, reading that here is cheaper than finding it out in week six. What is here instead is a number measured at every release, published with what it does not cover.

06

Anonymity and review

You are granting access to a firm that publishes no names

A fair objection, and most of the reason this page exists. The work is visible while it happens. The code is in your repositories from the first commit. Every change goes through your review, and the weekly demo runs on your real data.

Why we publish the numbers and not the names
07

Removing us

You can end the engagement and keep the system running

A vendor you cannot remove is a risk of its own. The code is already yours, the gate is wired into your change process, and the runbook is written for whoever is on call. You can end the monthly rate and keep running.

What the handover leaves you holding
Five translucent violet quadcopters ringed around a faceted glass block at the centre, each firing one thin beam from its nose into the block so the beams form a five-spoke star.
More than one reader on the same target, because a single check that passes is not evidence.

Ask the rest

If your security review has a question this page does not answer, put it in the first message.

Start a project

Send the question this page did not answer

If your security review needs something that is not written here, ask it before an NDA. You get a straight answer, including when the answer is that we are the wrong vendor.