GatewayEnforcer
Security Architecture

Six properties. None of them are promises.

Most AI vendors answer a security questionnaire with policy. GatewayEnforcer answers it with architecture — properties that hold even if you assume the vendor is hostile. That assumption is the design requirement.

01In-tenant deploymentYour subscription, your boundary

The control plane runs inside your own Azure subscription. Data never crosses your security boundary, because there is no other side to cross to: Heaviside AI operates no servers in the data path.

02Memory-only executionVolatile by construction

Prompts, responses, and intermediate state are processed in volatile memory. Nothing is written to disk, cache, or log storage during AI session handling. Non-retention isn’t a deletion job that runs later — it’s the absence of a write. On Gateway Sessions Pro, the call record you keep is written only to storage in your own subscription.

03SDIP-6™ sanitizationSix passes before reclamation

On session termination, a six-pass cryptographic sanitization routine overwrites session buffers before memory is reclaimed — informed by NIST 800-88 media-sanitization principles, applied to volatile memory. The protocol is the subject of two U.S. provisional patent applications.

04Certificate of Incineration™Evidence, not assurance

Every session closes with a SHA-256 signed receipt attesting to session start, termination, and sanitization. An auditor or a court can verify it without asking us anything. Receipts are non-repudiable — attested by the customer’s own identity provider, with the vendor excluded from the trust chain by architecture.

05American-only model routingLocked on the Financial and Federal plans

On the Financial and Federal plans, the gateway admits American-hosted providers only and refuses every other provider. API keys stay with you. Which providers make the roster is governed by the published AI Provider Admission Standard.

06Zero-trust operator postureWe designed ourselves out

Heaviside AI holds no customer keys, no customer data, no session content. We cannot be subpoenaed for what we structurally do not possess — and neither can anyone who compromises us. The vendor is not in your threat model because the vendor is not in your data path.

The Honest Line

What we claim — and what we don’t.

We never claim compliance or accreditation. We hand you the architecture and the evidence — independently verifiable — and the legal conclusions belong to your counsel.

See how the architecture maps to GSAR 552.239-7001, the Presidential AI doctrine, and the EU AI Act →

Prove It Yourself

The Sessions page runs a live demonstration in your browser.

Watch a session end and see the signed certificate it leaves. Nothing leaves the page — which is the entire point.