Trust must be auditable Trust Center
Enterprise AI only matters when it is built on trust. TazMemory.AI wraps the entire data lifecycle — from personal data to model output — in layered protections. This page transparently documents the standards we apply, our PII protection model, and the AI guardrail architecture.
Last updated: July 2025
Compliance & Certifications
The standards and frameworks below form the foundation of the product architecture. Controls marked 'Ready' are implemented in the platform; 'Roadmap' items are on the release plan and available for early access on request.
KVKK
Turkish Data Protection Law 6698
Control sets for explicit consent, transparency notices, and data subject rights across collection, storage, transfer, and deletion of personal data.
publicTürkiye
GDPR
EU 2016/679
Legitimate interest and consent bases, access/erasure/rectification rights, and SCCs for cross-border data transfer.
publicEuropean Union
ISO 27001
Information Security Management
ISO/IEC 27001 controls across risk assessment, access control, cryptography, and incident management.
publicGlobal
SOC 2
Type II
Independent audit against security, availability, processing integrity, confidentiality, and privacy principles.
publicGlobal
On-Prem
On-Premise Install
Data and model weights remain in the customer's own data center, including an air-gapped option.
publicCustomer
NIS2
EU Networks Directive
Risk management and incident reporting obligations for critical infrastructure providers.
publicEU
PII Protection
Personally identifiable information is protected at every point — from intake, to model context, to output, to audit logs. PII is classified independently of content, masked, and only revealed within an authorized context.
routeData Flow & PII Lifecycle
User prompt and attached documents are received.
The PII classifier flags identity, contact, financial, and health data.
Sensitive fields are tokenized/redacted; originals are encrypted with the tenant key.
Masked context is sent to the isolated tenant workspace.
The output PII filter catches any leaked data and re-applies masking.
No PII is written to audit logs; only metadata is retained.
categoryClassified PII Categories
Identity
National ID, passport, license, date of birth
Contact
Email, phone, address
Financial
IBAN, card number, credit details
Health
Diagnosis, prescription, health record (special category)
Biometric
Fingerprint, face, voice (special category)
Location
GPS coordinates, IP, device ID
shieldProtection Layers
Tokenization
Sensitive values are mapped to reversible tokens keyed per tenant; the model never sees raw data.
Redaction
Unnecessary PII is removed from the prompt entirely; least-privilege is enforced.
Encryption
AES-256 at rest, TLS 1.3 in transit; keys are managed per tenant via KMS.
Retention Minimization
PII is kept only as long as needed for the purpose; auto-deleted when the period expires.
Access Restriction
PII access is gated by RBAC + approval flow; every access is written to audit.
gavelData Subject Rights (KVKK Art. 11 / GDPR 15-22)
Access
Learn whether personal data is being processed.
Rectification
Request correction of incomplete or inaccurate data.
Erasure
Request deletion when the processing purpose has ended.
Objection
Object to processing, especially for direct marketing.
Portability
Receive personal data in a structured format.
Withdraw Consent
Withdraw consent for processing based on explicit consent.
scheduleRetention & Deletion Periods
| Data Type | Period | Note |
|---|---|---|
| Conversation content | Tenant policy (default 90 days) | Admin-configurable; resettable. |
| Audit logs | 6 months – 2 years | Immutable (WORM) storage; extendable per regulation. |
| CV / application data | Position duration + 6 months | Per KVKK privacy notice. |
| Backups | 30 days | Encrypted; auto-destroyed when the period expires. |
AI Guardrails
Guardrails are the layered defense that constrains what the model sees, produces, and which tools it may invoke. Every request passes through input → model → output → tool layers and is halted if it violates tenant policy.
shield_personLayered Guardrail Architecture
Input Layer
The user prompt is processed before reaching the model.
Model Layer
Model context and system behavior are protected.
Output Layer
Model output is validated before returning to the user.
Tool & Function Layer
Agent-invoked tools are sandboxed.
Traffic & Quota
Abuse and burst load are prevented.
radarThreat Detection Techniques
| Threat | Technique | Automated Action |
|---|---|---|
| warningPrompt Injection | Injection signatures + suspicious-instruction heuristics | blockPrompt redacted / request blocked |
| warningJailbreak | Role-breaking patterns + context-coherence scoring | blockFalls back to system prompt |
| warningPII Leakage | Output NER + mask-consistency check | blockValue masked / output blocked |
| warningToxic Content | Multi-classifier + threshold scoring | blockFiltered / alternate response |
| warningUnauthorized Tool Call | Allowlist + schema validation | blockCall blocked, audit written |
| warningSensitive Topic | Topic classifier (legal/financial/health) | blockRedacted / responsible-use notice |
Architecture & Isolation
Security starts in the architecture, not in a single control. The pillars below keep tenant data isolated from each other and from the outside world.
Data Isolation
Each tenant's data is separated logically and physically; query paths enforce a tenant filter by default.
Multi-Tenant
Even on shared infrastructure, context isolation is per tenant; cross-tenant leakage is prevented.
On-Premise
Data and model weights stay in the customer's data center; air-gapped option available.
JWT + Refresh
Short-lived access tokens with rotating refresh; session-theft hardening.
RBAC
Least privilege; role-based, resource-scoped, permission-code-level access.
Audit Log
Immutable (WORM) records — who, when, what, all traceable.
Encryption
AES-256 at rest, TLS 1.3 in transit; per-tenant KMS key management.
Guardrail Gate
Every AI call passes through a central guardrail gate enforced by the policy engine.
Security Operations
The processes where controls live — what we do when a vulnerability is found, how we notify on breach, and how we monitor continuously.
Incident Response
Tiered incident plan: detect → triage → contain → recover, with defined SLAs.
Breach Notification
Notification to the authority and data subjects within 72 hours per KVKK; GDPR 33/34 aligned.
Vulnerability Management
Findings → CVSS scoring → patch SLA; fast-track patching for critical issues.
Penetration Testing
Regular internal/external pen tests and threat-modeling workshops.
Continuous Monitoring
SIEM-based log correlation, anomaly detection, and 24/7 alert routing.
Vendor Security
Subprocessor security assessment, DPIAs, and contractual guarantees.
Infrastructure & Subprocessors
The infrastructure and subprocessors used to deliver the service. In on-premise installs this list is replaced by the customer's own infrastructure.
| Category | Provider | Purpose | Location |
|---|---|---|---|
| Hosting | Customer infra (on-prem) / approved cloud | Compute and storage | Customer-controlled / TR & EU |
| LLM Provider | 12+ providers (OpenAI, Anthropic, Google, local models) | Model inference | Routed by tenant policy |
| Vector DB | Tenant-specific index | RAG embeddings | Tenant data region |
| SMTP relays | Transactional email and notifications | EU | |
| Monitoring | SIEM / log tooling | Security log correlation | Tenant region |
Frequently Asked Questions
Where is my data stored?expand_more
Does the model learn my personal data?expand_more
How are you protected against prompt injection?expand_more
How quickly do you notify on a KVKK breach?expand_more
Can another tenant access my data?expand_more
How long are audit logs kept?expand_more
I found a security issue — what should I do?expand_more
Let's build trust together
Found a vulnerability, need audit documentation, or have a custom compliance need? Our security team responds transparently and fast.