Vault execution
Requests are executed in the protected, hardware-isolated Vault execution environment.
Security
Vault routes execute requests in a protected, hardware-isolated environment. Sealarca verifies the attestation of that environment and the receipt associated with every inference.
This page explains what Sealarca controls, what is processed inside the protected execution environment and what remains the responsibility of your environment or tools.
Model training: lack of logging alone does not establish this commitment. Ask for the contractual terms applicable to your use before sending sensitive documents.
Understand the infrastructureDocumented safeguards · common Vault standard
Vault routes execute requests in a protected, hardware-isolated environment. Capabilities, limits and pricing remain those of the selected model.
Requests are executed in the protected, hardware-isolated Vault execution environment.
Sealarca verifies the attestation of that environment and the receipt associated with every inference.
Sealarca does not log the content of prompts and responses.
Account, usage, billing and diagnostic information remains distinct from processed content.
Before forwarding any request for execution, Sealarca checks that the trust environment and channel associated with the route meet Vault requirements. If this check fails or is unavailable, the inference is refused without fallback to an unprotected route. The Vault receipt then links the response to the verified route and session.
A final proof can be downloaded as a signed bundle. The signature guarantees its integrity and Sealarca origin; by itself, it is not an independent hardware verification.
View API examplesOperational data
Sealarca separates the text entrusted to the model from the information strictly required to authorize the call, measure usage and operate the service.
This data is limited to its purpose and applicable legal obligations. Accounting data may be retained for up to ten years where required by Swiss law.
On the application side
Desk and Bridge reduce data exposure before a call reaches Sealarca, using mechanisms suited to their respective purposes.
Desk keeps documents, profiles and traces locally. Dossier analyses aggregate current profiles without sending text; explicit profile generation sends Markdown to Sealarca and chat sends selected context. Local traces retain references, counts and notices without copying document text.
View the Desk pageProtects the key at rest through the operating system’s secure storage and configures compatible applications temporarily.
View the Bridge pageScope of protection
Sealarca’s protection has a defined scope. It does not replace the security of your environment or human review of results.
Processing countries, any subprocessors and specific conditions are communicated in the contract and, where applicable, in the DPA.
Sealarca
Start with your Sealarca account, then choose Desk, Bridge or the API according to the way you work.