Skip to content

Security

Understand what is protected — and where protection ends.

Vault routes execute requests in a protected, hardware-isolated environment. Sealarca verifies the attestation of that environment and the receipt associated with every inference.

This page explains what Sealarca controls, what is processed inside the protected execution environment and what remains the responsibility of your environment or tools.

Five answers before you start

What is sent?
Desk keeps documents, profiles and traces locally. Dossier analyses aggregate current profiles without sending text; explicit profile generation sends Markdown to Sealarca and chat sends selected context. Local traces retain references, counts and notices without copying document text.
How is execution protected?
The service checks the trusted environment and channel before transmission. Content is processed in the protected Vault execution environment.
What is retained?
The gateway does not log prompts or responses. Operational metadata and proofs may be retained; Desk keeps your history locally.
Where does processing take place?
Applicable countries and conditions are defined in the contract and DPA, the data protection agreement. Swiss branding is not a blanket promise of processing in Switzerland.
What are the limits?
Execution protection does not guarantee answer accuracy or workstation security. Check results and your organisation’s requirements.

Model training: lack of logging alone does not establish this commitment. Ask for the contractual terms applicable to your use before sending sensitive documents.

Understand the infrastructure

Documented safeguards · common Vault standard

What Sealarca protects

Vault routes execute requests in a protected, hardware-isolated environment. Capabilities, limits and pricing remain those of the selected model.

Vault execution

Requests are executed in the protected, hardware-isolated Vault execution environment.

Associated verification

Sealarca verifies the attestation of that environment and the receipt associated with every inference.

Content not logged

Sealarca does not log the content of prompts and responses.

Content separate from operations

Account, usage, billing and diagnostic information remains distinct from processed content.

Verification associated with every inference.

Before forwarding any request for execution, Sealarca checks that the trust environment and channel associated with the route meet Vault requirements. If this check fails or is unavailable, the inference is refused without fallback to an unprotected route. The Vault receipt then links the response to the verified route and session.

pending — Verification in progress
Try again after a short delay.
verified — Proof verified
The Vault checks associated with the inference succeeded.
failed — Proof not verified
Do not treat the result as verified.
expired — Proof expired
The retention period has ended.

A final proof can be downloaded as a signed bundle. The signature guarantees its integrity and Sealarca origin; by itself, it is not an independent hardware verification.

View API examples

Operational data

What the service needs to know to operate

Sealarca separates the text entrusted to the model from the information strictly required to authorize the call, measure usage and operate the service.

Protected content

  • Prompt and documents sent to the model
  • Response generated inside Vault

Operational data

Account and access
Status, rights and key reference required for authorization.
Request and model
Identifier, requested model, used model and status.
Consumption
Input, output and cache tokens when reported.
Cost and credits
Call cost and movements required for billing.
Security and support
Timestamp, duration and technical information required for diagnosis.

This data is limited to its purpose and applicable legal obligations. Accounting data may be retained for up to ten years where required by Swiss law.

On the application side

What about the application?

Desk and Bridge reduce data exposure before a call reaches Sealarca, using mechanisms suited to their respective purposes.

Sealarca Desk

Desk keeps documents, profiles and traces locally. Dossier analyses aggregate current profiles without sending text; explicit profile generation sends Markdown to Sealarca and chat sends selected context. Local traces retain references, counts and notices without copying document text.

View the Desk page

Sealarca Bridge

Protects the key at rest through the operating system’s secure storage and configures compatible applications temporarily.

View the Bridge page
View application data

Scope of protection

What remains outside the Sealarca boundary

Sealarca’s protection has a defined scope. It does not replace the security of your environment or human review of results.

  • Models may produce inaccurate, incomplete or unpredictable responses.
  • Capabilities, context limits and availability vary by model.
  • The device, browser and client applications remain outside the Vault perimeter.
  • The client must have the rights and legal bases required to submit the data.

Processing countries, any subprocessors and specific conditions are communicated in the contract and, where applicable, in the DPA.

Sealarca

Ready to use Sealarca?

Start with your Sealarca account, then choose Desk, Bridge or the API according to the way you work.

Start