Security

Enterprise-Grade Security Your IT Team Can Verify

Enterprise software with enterprise controls, documented in a security posture file built for vendor due diligence. Every claim here is checkable.

Standing Access for Hallian
None
support access only with your written authorization
Encryption in Transit
TLS 1.2+
enforced at every network entry point
Stored Secrets
Encrypted
keys, credentials, and integration secrets
Regulated Environments

CMMC-aligned due diligence, supported

HallianAI routes AI inference through your own cloud accounts, including FedRAMP High authorized government environments. Our Posture Document maps platform behavior to NIST SP 800-171 controls for your vendor reviews and System Security Plan.

  • Inference can route through FedRAMP High authorized government clouds.
  • Posture Document maps platform behavior to NIST SP 800-171 controls.
CMMC-AlignedTLS 1.2+ encrypted in transitFedRAMP High authorized clouds
Controls

Enterprise controls, your infrastructure

Every control below is built into HallianAI and governed by your administrators.

Role-Based Access Control

Two tiers govern everything: what users can do, and which knowledge they can reach. Least privilege by design.

Two-Factor Authentication

Enforced for every account, under policy your administrators set.

Encryption

TLS 1.2+ in transit at every entry point. Sensitive keys and secrets are encrypted at rest on the infrastructure layer.

Audit Logging

Logins, AI queries, workflow runs, and admin changes, stored in your database. Retention from one month to indefinite.

Controlled Updates

Versioned packages with release notes. No update is applied to your environment until you authorize it.

Governed Integrations

MCP connections authenticate with encrypted credentials you supply. You decide what connects.

The one line we never cross

Your documents, indexes, conversations, and logs live inside your environment, in a database you control. When someone asks a question, that question and the excerpts needed to answer it go over an encrypted connection to your own cloud AI account. The answer comes home and is stored in your database.

Nothing goes to Hallian. We hold no keys, see no usage, and keep no copies. We own the software. You own the environment. That line is documented, not assumed, in our Security and Privacy Posture Document.

See the full privacy architecture

We have been having a blast with HallianAI today. I think it will quickly become the go-to for our IT department on getting answers for our internal systems.

Director of ISBA
North Greenville University
Verify It Yourself

Bring your hardest questions

We will walk your technical team through the architecture and the documentation, line by line.