Skip to content

Security and deployment

The deployment model is the security model.

TA Msev runs as containers in your AWS account. Source permissions drive retrieval, model calls stay on endpoints you configure, and every query is auditable.

Deployment

Everything inside your account boundary

Marketplace subscription delivers images and CloudFormation or Terraform templates. You choose regions, VPCs, and KMS keys.

01

Corporate network

users + IdP

SSO (SAML / OIDC)CI runners

Your AWS account · VPC

02

Clearance

sync + index

S3 / Confluence / Drive connectorsACL-aware vector indexKMS encrypted storage

03

Baseline

eval API

golden suite runnerJUnit + gate CLIresults in your account

04

Model endpoint

your choice

Amazon Bedrockor private model service
Illustrative topology. Actual resources depend on your template choices and scaling configuration.

Controls

What security teams ask for first

  • Runs in your VPC

    Containers deploy into subnets you designate. You control security groups, endpoints, and egress.

  • No data egress to TA Msev

    Documents, embeddings, queries, model payloads, and audit logs remain in your AWS account.

  • Your identity provider

    SAML or OIDC sign-in. Group membership from your IdP drives retrieval filters without a parallel user database.

  • Encryption with your keys

    Data at rest uses AWS KMS keys you control. TLS between all internal components and to model endpoints.

  • Queryable audit trail

    Each request records identity, candidates, filtered documents, citations, and request IDs for SIEM correlation.

  • Least-privilege IAM

    Deployment templates scope roles to the buckets, secrets, and log groups the workloads need, and nothing broader.

Audit logging

One JSON object per query

Security and support teams can answer who asked, what was considered, what was filtered, and what was cited without replaying production traffic.

audit-log · one queryExample
{  "ts": "2026-09-30T14:07:21Z",  "event": "retrieval.query",  "user": "alice@example.com",  "groups": ["sre-payments", "all-staff"],  "candidates": 4,  "authorized": 3,  "filtered": [    {      "doc": "confluence://LEGAL/payments-disclosure",      "reason": "no_matching_principal"    }  ],  "cited": [    "confluence://SRE/payments-runbook",    "s3://policies/incident-response.pdf"  ],  "request_id": "q_7f3a9c21"}

Compliance

Roadmap and current capabilities

We do not claim certifications we have not completed. The table below reflects what is available today and what is planned.

Available now

  • VPC deployment with customer-managed KMS
  • SSO via SAML/OIDC
  • Audit logs to CloudWatch Logs or S3
  • AWS Marketplace procurement

In progress

  • SOC 2 Type II readiness program
  • Detailed control mapping documentation for customer assessments

On the roadmap

  • FedRAMP-oriented deployment patterns (customer-led)
  • HIPAA BAA availability subject to AWS Marketplace terms

FAQ

Security FAQ

Walk through deployment in your account.

We review VPC layout, IAM boundaries, IdP integration, and sample audit exports with your security team on the call.