Skip to content

Deployment and security

Your documents stay yours

The grounding service runs as an isolated instance on the cloud and in the region you choose. Your documents stay inside your environment. This page sets out what that means, and what gets decided with you rather than for you.

What does an isolated instance mean?

Each customer gets a separate instance of the grounding service rather than a tenant inside a shared one. Your corpus is not pooled with anyone else's, it is not used to train anything, and there is no path by which one customer's documents can inform another customer's answers. The separation is architectural, not a permissions setting layered over shared storage.

The instance runs on infrastructure you choose. That can be your own cloud account, in the region your policy requires, and it can be your own hardware where nothing is permitted to leave the building at all. We do not have a preferred answer here and we do not need one, because a grounded domain does not require a frontier-scale model to answer it well. The service is small enough that where it runs is genuinely your decision.

What does the model provider see?

Only what your own configuration sends it. The grounding service does the retrieval; a language model writes the sentence at the end. Which model that is, and where it runs, is a choice you make at scoping. If your policy is that no document text may reach a third-party model, the answer is a model endpoint inside your own environment, and the grounding service works the same way underneath it.

This is worth saying plainly because it is the question that stalls most industrial AI projects, and the honest answer is that it is a deployment decision rather than a property of the technology. We will tell you what each option costs you in practice, including when the stricter option is the harder one to run.

What is settled before any document is ingested?

Most pilots that fail do not fail on the technology. They fail because a data access problem surfaced after the technical work was finished, which is late enough that the work has to be redone or abandoned. So these are written down first, as part of scoping, and none of them are our decision alone.

What cannot leave your environment
Named document by document or system by system, in writing, before anything is ingested. If a class of document cannot cross a boundary, it does not enter the corpus slice.
What needs masking
Personal data, commercially sensitive terms, and anything else you identify. Agreed before ingestion rather than discovered in an output.
Which model endpoint answers
Yours or ours, hosted or local. The grounding service is model-agnostic, so this is a policy decision rather than a technical constraint.
Who can see what
Access policy and tenant scope, set with your own identity and access rules rather than alongside them.
How long anything is kept
Retention and deletion, including what happens to an ingested corpus when a pilot ends and the answer is no.
Who is in the room for it
Your IT and security people, at scoping. Not shown the result afterwards.

What about auditability?

Every answer the grounding service produces carries the sources it was built from and a coverage report saying what it did not use. That record is the audit trail, and it exists whether or not anyone asks for it, which means an answer given in March can be examined in November against the revision that governed at the time.

Documents that could not be read cleanly are flagged for human review rather than guessed at, and the decision a person made about each one is kept. See how it works for the mechanism, and traceability for why the property matters more than it sounds.

What we do not claim

Lodestone Labs is an early-stage company and this page does not assert certifications the company does not yet hold. What it describes is how the service is built and deployed, and what is agreed in writing before your documents are touched. If your procurement process needs a specific attestation, tell us which one at the first conversation rather than at the end, and we will tell you straight whether we can meet it and by when.

If your security review has questions this page does not answer, send them. We would rather answer them before a pilot is scoped than discover them inside one.

Send us your security questions