Trust & Security

Governance is the product

Most AI platforms ask you to trust them with your data. Blue Mesh is built so you do not have to: the platform runs where your data already lives, under controls you already govern, and it writes down everything it does. This page sets out how, and it is equally plain about what we do not claim.

you own ityou govern itit stays private
ENVIRONMENT
Yours
private cloud · on-premises · air-gapped
PLATFORM
Agents · Voice · RAG · Training
runs inside it
OWNERSHIP
Your data · Your models · Your systems
RECORD
Every decision, logged
audit trail
the whole stack, in one linenothing here requires our cloud
01
Deployment

It runs where your data lives

Three deployment modes, and the difference between them is not pricing tiers. It is how much of the outside world can reach the system, and what your team keeps control of in each case.

Private cloud

Blue Mesh deploys into your own VPC. Model weights and inference stay inside your network boundary, and your cloud team keeps its existing controls.

On-premises

The platform runs in your data center, on your hardware. Nothing about it requires an outbound connection to us.

Fully air-gapped

For data that cannot leave: BM in a Box ships pre-configured on NVIDIA DGX, with no path to the internet. No automatic updates and no telemetry home.

02
Security & controls

Named controls, not adjectives

A security review never asks whether a platform is secure. It asks what the controls are, where they apply, and what evidence exists afterward. These are the answers, stated so your reviewer can check them.

Role-based access

Who can build, run, approve, and read is a role assignment, not a convention. When your auditor asks who could have triggered an action, the answer is a list, not an interview.

Encryption

Data is encrypted in transit and at rest, inside your environment. We put it that plainly because the fashionable absolute versions of this claim do not survive a deployment diagram, and yours will be checked against one.

Audit trail on every decision

Every decision and result is logged for compliance audit: what ran, what it read, what it did, who approved it. When a regulator or a customer asks what the system did and why, the answer is on record rather than reconstructed.

Human checkpoints

Consequential actions pause for a person before they execute, at thresholds you configure. Most serious platforms have an approval gate now; the real comparison is how finely it can be scoped, and here that is per action, per workflow.

03
Ownership

Yours means yours

The quiet failure mode of enterprise AI is discovering, two years in, that the models trained on your data belong to someone else. Blue Mesh is structured so the question never comes up.

Your data

It stays inside the boundary you deploy into, under your retention rules. The platform indexes and reads it in place; it does not siphon it to a vendor cloud.

Your models

Fine-tune on your own data with BM Oasis and the resulting weights are yours, not licensed back to you. They stay inside the boundary they were trained in.

Your systems

Agents work through the tools you already run, 300+ systems and counting, under the same credential discipline your team already enforces. Nothing gets rebuilt in our image.

04
Compliance

Certifications your build can carry

Applications built and run on Blue Mesh can be taken through SOC 2, ISO 27001 and HIPAA. The platform brings the controls those audits test, inside your own environment, so the certification your product needs is a deployment question rather than a rewrite.

SOC 2

The controls a SOC 2 audit tests, access control, change management, and a log of who did what and when, come with the platform.

ISO 27001

An information security management system defines its scope and its evidence. Blue Mesh deploys inside yours, so what you build falls inside that boundary.

HIPAA

Patient data stays inside the boundary you already run, with access scoped by role and every read and write attributable.

What the log gives an auditor

Whatever framework you answer to, the audit trail is the raw material: every decision and result, attributable and timestamped, under your retention rules.

What we do not claim

No absolute security promises, and no pretending a human approval gate is unique to us. If a sentence here cannot survive your security review, we want it gone.

Where to go next
  • BM in a Box The air-gapped mode as a shippable object: pre-configured on NVIDIA DGX, no outbound connection required.
  • BM Oasis Model ownership in practice: fine-tune on your own data, keep the weights, serve them from your own infrastructure.
  • How we compare Fifty platforms on published sources, including the questions worth putting to every vendor on your shortlist.
  • Questions and answers Thirty questions answered plainly, including who Blue Mesh is not for and what we will not claim.
// bring your security review

Send us the questionnaire you already have

We will answer it in writing, against this page. If the deployment you need is the appliance, we will say so. If a private cloud is cheaper and sufficient, we will say that instead.