🇩🇪Frankfurt·EU sovereign

Security

Router-level guardrails, sovereignty posture, and compliance evidence. Every prompt and every response passes through us — this is where the wall gets shown.

Security PackCompliance PackConfidential Compute
Blocked today
8
PII redactions
34
Injection attempts
3
SSO coverage
47/47
MFA
Required
Region
🇩🇪 Frankfurt
TEE-attested

Data hygiene

What's leaving via prompts and what's coming back.

PII redaction (outbound)

Scans prompts sent to models for PII (email, phone, SSN, passport, health ID) and redacts before the model sees them.

Redact
27
24h
Enabled·12 patterns
Last: 3m ago
PII redaction (inbound)

Scans model responses for PII synthesized or regurgitated by the model and redacts before returning to the user.

Redact
7
24h
Enabled·12 patterns
Last: 2h ago
Secret detection

Detects and blocks credentials in prompts before they leave the workspace: AWS access keys, GitHub tokens, DB URLs, JWTs, generic API keys.

Block
1
24h
Enabled·24 patterns
Last: 23h ago
DLP custom patterns

Customer-defined regex + classifier patterns for sensitive company data (customer lists, compensation, contracts, product roadmaps).

Block
2
24h
Enabled·8 patterns
Last: 3h ago
Unsafe response filter

Classifies model responses for policy violations (violence, self-harm, illegal activity) and blocks or logs based on policy.

Log only
0
24h
Enabled·6 patterns
Last: 1d ago

Attack detection

Prompt injection, jailbreaks, and adversarial patterns — blocked before the model sees them.

Prompt injection (direct)

Detects user-typed instruction-override patterns ("ignore all previous instructions", role-play jailbreaks, system-prompt extraction).

Block
2
24h
Enabled·18 patterns
Last: 55m ago
Prompt injection (indirect / RAG)

Detects malicious instructions embedded in retrieved RAG documents (indirect prompt injection via Drive/SharePoint content).

Block
1
24h
Enabled·14 patterns
Last: 5h ago
Jailbreak classifier

ML classifier for adversarial prompt patterns that don't match a static rule (novel jailbreaks, DAN variants, encoded payloads).

Block
0
24h
Enabled·ML classifier
Last: 2d ago
Encoding obfuscation

Detects base64, hex, ROT13, and other encoded payloads used to exfiltrate data or smuggle jailbreak prompts past the classifier.

Log only
0
24h
Enabled·7 patterns
Last: 5d ago

Data placement

Where your data lives, under whose keys, and whether inference runs in a Trusted Execution Environment.

Sovereignty
Full map
Data plane
🇩🇪 Frankfurt · STACKIT
RAG index
🇩🇪 Frankfurt · STACKIT
Backups
🇩🇪 Frankfurt · STACKIT
Encryption at rest
Customer keys · STACKIT KMS
Inference endpoints (routing share)
🇩🇪FrankfurtSTACKIT
68%
🇫🇷ParisNebius
14%
🇫🇮MäntsäläNebius
12%
🇬🇧LondonNebius
4%
🇺🇸KansasNebius
2%
Confidential Compute
Enabled
100% attested
TEE
Intel TDX · TDX 1.5
Customer key
0x3f8a9e...b12c · with receipts

Compliance evidence

Control coverage across the frameworks your regulator asks about.

Next evidence pack
2026-Q4
Oct 1, 2026
Control coverage
93%
63 of 68 mapped
SIEM export
Splunk Cloud
pushed 47m ago
Retention
7 years
default 1y (extended)

Recent incidents

Latest security-category events from the audit log.