shield_lockTrust Center

Trust must be auditable Trust Center

Enterprise AI only matters when it is built on trust. TazMemory.AI wraps the entire data lifecycle — from personal data to model output — in layered protections. This page transparently documents the standards we apply, our PII protection model, and the AI guardrail architecture.

KVKK 6698GDPRISO 27001SOC 2On-Premise
AES-256
Encryption at rest
TLS 1.3
Encryption in transit
72h
Breach notification target
100%
Tenant data isolation

Last updated: July 2025

Compliance & Certifications

Compliance & Certifications

The standards and frameworks below form the foundation of the product architecture. Controls marked 'Ready' are implemented in the platform; 'Roadmap' items are on the release plan and available for early access on request.

verified

KVKK

Turkish Data Protection Law 6698

Active

Control sets for explicit consent, transparency notices, and data subject rights across collection, storage, transfer, and deletion of personal data.

publicTürkiye

verified

GDPR

EU 2016/679

Active

Legitimate interest and consent bases, access/erasure/rectification rights, and SCCs for cross-border data transfer.

publicEuropean Union

verified

ISO 27001

Information Security Management

Ready

ISO/IEC 27001 controls across risk assessment, access control, cryptography, and incident management.

publicGlobal

verified

SOC 2

Type II

Roadmap

Independent audit against security, availability, processing integrity, confidentiality, and privacy principles.

publicGlobal

verified

On-Prem

On-Premise Install

Active

Data and model weights remain in the customer's own data center, including an air-gapped option.

publicCustomer

verified

NIS2

EU Networks Directive

Roadmap

Risk management and incident reporting obligations for critical infrastructure providers.

publicEU

PII Protection

PII Protection

Personally identifiable information is protected at every point — from intake, to model context, to output, to audit logs. PII is classified independently of content, masked, and only revealed within an authorized context.

routeData Flow & PII Lifecycle

01
Intake

User prompt and attached documents are received.

02
Detect

The PII classifier flags identity, contact, financial, and health data.

03
Mask

Sensitive fields are tokenized/redacted; originals are encrypted with the tenant key.

04
Model

Masked context is sent to the isolated tenant workspace.

05
Output

The output PII filter catches any leaked data and re-applies masking.

06
Log

No PII is written to audit logs; only metadata is retained.

categoryClassified PII Categories

badge

Identity

National ID, passport, license, date of birth

contact_phone

Contact

Email, phone, address

credit_card

Financial

IBAN, card number, credit details

medical_information

Health

Diagnosis, prescription, health record (special category)

fingerprint

Biometric

Fingerprint, face, voice (special category)

public

Location

GPS coordinates, IP, device ID

shieldProtection Layers

token

Tokenization

Sensitive values are mapped to reversible tokens keyed per tenant; the model never sees raw data.

visibility_off

Redaction

Unnecessary PII is removed from the prompt entirely; least-privilege is enforced.

lock

Encryption

AES-256 at rest, TLS 1.3 in transit; keys are managed per tenant via KMS.

schedule

Retention Minimization

PII is kept only as long as needed for the purpose; auto-deleted when the period expires.

no_accounts

Access Restriction

PII access is gated by RBAC + approval flow; every access is written to audit.

gavelData Subject Rights (KVKK Art. 11 / GDPR 15-22)

visibility

Access

Learn whether personal data is being processed.

edit

Rectification

Request correction of incomplete or inaccurate data.

delete

Erasure

Request deletion when the processing purpose has ended.

block

Objection

Object to processing, especially for direct marketing.

sync

Portability

Receive personal data in a structured format.

cancel

Withdraw Consent

Withdraw consent for processing based on explicit consent.

scheduleRetention & Deletion Periods

Data TypePeriodNote
Conversation contentTenant policy (default 90 days)Admin-configurable; resettable.
Audit logs6 months – 2 yearsImmutable (WORM) storage; extendable per regulation.
CV / application dataPosition duration + 6 monthsPer KVKK privacy notice.
Backups30 daysEncrypted; auto-destroyed when the period expires.
AI Guardrails

AI Guardrails

Guardrails are the layered defense that constrains what the model sees, produces, and which tools it may invoke. Every request passes through input → model → output → tool layers and is halted if it violates tenant policy.

shield_personLayered Guardrail Architecture

input
1

Input Layer

The user prompt is processed before reaching the model.

check_circlePII detection and masking
check_circlePrompt injection signature/pattern detection
check_circleToxicity and hate-speech filter
check_circleTopic and usage restriction (tenant policy)
psychology
2

Model Layer

Model context and system behavior are protected.

check_circleJailbreak and role-manipulation resistance
check_circleSystem prompt leakage protection
check_circleSession/context isolation
check_circleModel isolation (per-tenant workspace)
output
3

Output Layer

Model output is validated before returning to the user.

check_circleOutput PII filter and re-masking
check_circleHallucination/redaction validation
check_circleToxicity output control
check_circleCategorical content modulation (legal/policy/financial)
build
4

Tool & Function Layer

Agent-invoked tools are sandboxed.

check_circleTool sandboxing (isolated execution)
check_circleFunction allowlist (approved APIs only)
check_circleParameter schema validation
check_circleHuman approval required for high-risk actions
speed
5

Traffic & Quota

Abuse and burst load are prevented.

check_circlePer-tenant rate limiting
check_circleToken and request budgets
check_circleBurst load protection
check_circleSuspicious pattern and anomaly detection

radarThreat Detection Techniques

ThreatTechniqueAutomated Action
warningPrompt InjectionInjection signatures + suspicious-instruction heuristicsblockPrompt redacted / request blocked
warningJailbreakRole-breaking patterns + context-coherence scoringblockFalls back to system prompt
warningPII LeakageOutput NER + mask-consistency checkblockValue masked / output blocked
warningToxic ContentMulti-classifier + threshold scoringblockFiltered / alternate response
warningUnauthorized Tool CallAllowlist + schema validationblockCall blocked, audit written
warningSensitive TopicTopic classifier (legal/financial/health)blockRedacted / responsible-use notice
Architecture & Isolation

Architecture & Isolation

Security starts in the architecture, not in a single control. The pillars below keep tenant data isolated from each other and from the outside world.

dns

Data Isolation

Each tenant's data is separated logically and physically; query paths enforce a tenant filter by default.

apartment

Multi-Tenant

Even on shared infrastructure, context isolation is per tenant; cross-tenant leakage is prevented.

home_work

On-Premise

Data and model weights stay in the customer's data center; air-gapped option available.

key

JWT + Refresh

Short-lived access tokens with rotating refresh; session-theft hardening.

badge

RBAC

Least privilege; role-based, resource-scoped, permission-code-level access.

history_edu

Audit Log

Immutable (WORM) records — who, when, what, all traceable.

lock

Encryption

AES-256 at rest, TLS 1.3 in transit; per-tenant KMS key management.

shield_person

Guardrail Gate

Every AI call passes through a central guardrail gate enforced by the policy engine.

Security Operations

Security Operations

The processes where controls live — what we do when a vulnerability is found, how we notify on breach, and how we monitor continuously.

crisis_alert

Incident Response

Tiered incident plan: detect → triage → contain → recover, with defined SLAs.

campaign

Breach Notification

Notification to the authority and data subjects within 72 hours per KVKK; GDPR 33/34 aligned.

bug_report

Vulnerability Management

Findings → CVSS scoring → patch SLA; fast-track patching for critical issues.

shield

Penetration Testing

Regular internal/external pen tests and threat-modeling workshops.

monitoring

Continuous Monitoring

SIEM-based log correlation, anomaly detection, and 24/7 alert routing.

verified

Vendor Security

Subprocessor security assessment, DPIAs, and contractual guarantees.

Infrastructure & Subprocessors

Infrastructure & Subprocessors

The infrastructure and subprocessors used to deliver the service. In on-premise installs this list is replaced by the customer's own infrastructure.

CategoryProviderPurposeLocation
HostingCustomer infra (on-prem) / approved cloudCompute and storageCustomer-controlled / TR & EU
LLM Provider12+ providers (OpenAI, Anthropic, Google, local models)Model inferenceRouted by tenant policy
Vector DBTenant-specific indexRAG embeddingsTenant data region
EmailSMTP relaysTransactional email and notificationsEU
MonitoringSIEM / log toolingSecurity log correlationTenant region
infoData residency follows the customer's tenant policy and chosen deployment model. In on-premise mode, data never leaves the customer's data center.
FAQ

Frequently Asked Questions

Where is my data stored?expand_more
In cloud installs, in the region selected by your tenant policy (TR or EU first); in on-premise installs, in your own data center — it never leaves.
Does the model learn my personal data?expand_more
No. PII is classified and tokenized/redacted before being sent to the model. The model sees masked context; originals remain encrypted with your tenant key.
How are you protected against prompt injection?expand_more
The input layer detects injection via signatures and suspicious-instruction heuristics; the model layer resists jailbreaks; the output layer checks for PII leakage. Suspicious requests are blocked and audited.
How quickly do you notify on a KVKK breach?expand_more
We target notification to the authority and affected data subjects within 72 hours, aligned with GDPR Articles 33/34.
Can another tenant access my data?expand_more
No. All query paths enforce a tenant filter by default; cross-tenant access is architecturally blocked and monitored.
How long are audit logs kept?expand_more
By default 6 months to 2 years, in immutable (WORM) storage; extendable per regulation. No PII is written to logs.
I found a security issue — what should I do?expand_more
Reach our security team via the 'Report a Vulnerability' link below. We handle it under our responsible disclosure program.

Let's build trust together

Found a vulnerability, need audit documentation, or have a custom compliance need? Our security team responds transparently and fast.