Security and deployment
The deployment model is the security model.
TA Msev runs as containers in your AWS account. Source permissions drive retrieval, model calls stay on endpoints you configure, and every query is auditable.
Deployment
Everything inside your account boundary
Marketplace subscription delivers images and CloudFormation or Terraform templates. You choose regions, VPCs, and KMS keys.
01
Corporate network
users + IdP
Your AWS account · VPC
02
Clearance
sync + index
03
Baseline
eval API
04
Model endpoint
your choice
Controls
What security teams ask for first
Runs in your VPC
Containers deploy into subnets you designate. You control security groups, endpoints, and egress.
No data egress to TA Msev
Documents, embeddings, queries, model payloads, and audit logs remain in your AWS account.
Your identity provider
SAML or OIDC sign-in. Group membership from your IdP drives retrieval filters without a parallel user database.
Encryption with your keys
Data at rest uses AWS KMS keys you control. TLS between all internal components and to model endpoints.
Queryable audit trail
Each request records identity, candidates, filtered documents, citations, and request IDs for SIEM correlation.
Least-privilege IAM
Deployment templates scope roles to the buckets, secrets, and log groups the workloads need, and nothing broader.
Audit logging
One JSON object per query
Security and support teams can answer who asked, what was considered, what was filtered, and what was cited without replaying production traffic.
{ "ts": "2026-09-30T14:07:21Z", "event": "retrieval.query", "user": "alice@example.com", "groups": ["sre-payments", "all-staff"], "candidates": 4, "authorized": 3, "filtered": [ { "doc": "confluence://LEGAL/payments-disclosure", "reason": "no_matching_principal" } ], "cited": [ "confluence://SRE/payments-runbook", "s3://policies/incident-response.pdf" ], "request_id": "q_7f3a9c21"}Compliance
Roadmap and current capabilities
We do not claim certifications we have not completed. The table below reflects what is available today and what is planned.
Available now
- VPC deployment with customer-managed KMS
- SSO via SAML/OIDC
- Audit logs to CloudWatch Logs or S3
- AWS Marketplace procurement
In progress
- SOC 2 Type II readiness program
- Detailed control mapping documentation for customer assessments
On the roadmap
- FedRAMP-oriented deployment patterns (customer-led)
- HIPAA BAA availability subject to AWS Marketplace terms
FAQ
Security FAQ
Walk through deployment in your account.
We review VPC layout, IAM boundaries, IdP integration, and sample audit exports with your security team on the call.