Most AI vendors answer a security questionnaire with policy. GatewayEnforcer answers it with architecture — properties that hold even if you assume the vendor is hostile. That assumption is the design requirement.
The control plane runs inside your own Azure subscription. Data never crosses your security boundary, because there is no other side to cross to: Heaviside AI operates no servers in the data path.
Prompts, responses, and intermediate state are processed in volatile memory. Nothing is written to disk, cache, or log storage during AI session handling. Non-retention isn’t a deletion job that runs later — it’s the absence of a write. On Gateway Sessions Pro, the call record you keep is written only to storage in your own subscription.
On session termination, a six-pass cryptographic sanitization routine overwrites session buffers before memory is reclaimed — informed by NIST 800-88 media-sanitization principles, applied to volatile memory. The protocol is the subject of two U.S. provisional patent applications.
Every session closes with a SHA-256 signed receipt attesting to session start, termination, and sanitization. An auditor or a court can verify it without asking us anything. Receipts are non-repudiable — attested by the customer’s own identity provider, with the vendor excluded from the trust chain by architecture.
On the Financial and Federal plans, the gateway admits American-hosted providers only and refuses every other provider. API keys stay with you. Which providers make the roster is governed by the published AI Provider Admission Standard.
Heaviside AI holds no customer keys, no customer data, no session content. We cannot be subpoenaed for what we structurally do not possess — and neither can anyone who compromises us. The vendor is not in your threat model because the vendor is not in your data path.
We never claim compliance or accreditation. We hand you the architecture and the evidence — independently verifiable — and the legal conclusions belong to your counsel.
Watch a session end and see the signed certificate it leaves. Nothing leaves the page — which is the entire point.