Security that starts with where the model runs.

Most AI security is about protecting data on its way to someone else’s servers. TinyWeights takes that journey out of the picture. Our models run inside your environment, so the questions your security team asks become simpler — and the answers become things they can check for themselves.

What crosses your network

A short list, by design.

Security reviews usually begin with a data-flow diagram. Ours is brief, because the work happens where your data already lives. Here is what each kind of information does in a TinyWeights deployment.

Questions and prompts

Stays local

Handled by the model on your hardware. Nothing is forwarded to an outside service for processing.

Documents and files

Stays local

Read where they are stored. There is no upload step and no copy held by TinyWeights.

Generated results

Stays local

Written to the places you choose — your screen, your disk, your systems — and nowhere else.

Activity records

Stays local

Kept inside your environment, where your own monitoring and retention rules apply.

Licence status

Account only

Where a product needs to confirm a licence, the check concerns your account — never the content you work with.

Your security team does not need to rely on this table: the checks further down this page show how to confirm it independently.

How protection is built in

Four layers, all under your control.

Compact models make a different security posture possible. Because they need modest hardware, they can sit inside the same walls, networks and rules that already protect your most sensitive systems.

Local processing

The model runs on equipment you choose: a laptop, a workstation, your own servers or a private cloud account. Sensitive work never depends on an outside provider being available or trustworthy.

Ready for isolation

Deployments can be planned for sites with no internet connection at all. New versions arrive as packages your team inspects and installs on its own schedule.

Your access rules

We design deployments around the sign-in and permission systems you already run, so the people who can use the model are the people you have already approved.

Records you keep

Usage and system events are written inside your environment and can feed the monitoring tools your team already watches, under retention periods you set.

Verification

Don’t take our word for it. Check it.

Trust should rest on evidence your own team gathers. These are the checks we encourage during any evaluation, and we are glad to walk through each one with you.

  1. Watch the traffic

    Run the software behind your firewall and inspect its network activity with the tools you already use. The content you process should never appear.

  2. Disconnect and carry on

    For products built to work offline, switch the connection off once set-up is complete. The work continues, because it never needed to leave.

  3. Review the architecture

    We walk your team through every component, dependency and data flow in a deployment, and answer questions in writing for your records.

  4. Put it under pressure

    Commission an independent test, or ask for our AI Security & Red Teaming service to probe the system before it goes live.

Regulation

Fewer parties, simpler obligations.

Many data-protection rules become harder the moment information passes to an outside processor. Keeping AI in-house removes that step, which shortens the paperwork for several common frameworks.

GDPR

Personal data in Europe

No transfer of personal data to an AI provider, so there is no extra processor or cross-border transfer to assess.

HIPAA

Patient information

Health records are analysed where they are held, rather than disclosed to a third-party service.

PCI DSS

Payment card data

Processing can sit inside your existing segmented card environment instead of extending it.

ISO/IEC 27001

Security management

One fewer external supplier to evaluate, monitor and include in your risk register.

SOC 2

Service assurance

Your confidential data stays outside any vendor’s systems, keeping supplier reviews focused and short.

NIST 800-171 · CMMC

Controlled information

Sensitive government-related data remains inside the boundary you have already defined and assessed.

These notes explain how local deployment supports each framework. Running software locally does not by itself make an organisation compliant, and TinyWeightsAI does not claim certifications it does not hold. We are happy to share what we can document for your assessment.

Shared responsibility

Clear lines between us.

Good security depends on everyone knowing their part. When the model runs in your environment, the split looks like this.

TinyWeightsAI looks after

  • Building and testing each release before it reaches you
  • Documenting the components and data flows of every deployment
  • Security fixes, with plain-language release notes
  • Guidance on hardening the machines the model runs on

Your organisation controls

  • The hardware, network and location the model runs in
  • Who can use the system and what data it can reach
  • Monitoring, backups and how long records are kept
  • When updates are approved and installed

Security questions

What reviewers usually ask.

Can TinyWeightsAI see our data?

Not through the product. In a local deployment the model processes information on your infrastructure, and we have no route to it. If you ever want our engineers to help with an issue, access happens only on terms you set, and you can end it at any time.

Can a deployment run with no internet connection?

Yes. Deployments can be designed for fully isolated sites. We agree the set-up and update process with your team during scoping so it fits your existing procedures.

How do updates reach us?

As versioned releases with notes describing what changed. Your team decides when to install them, and can test each one in a separate environment first.

Does a small model mean weaker protection?

No. Size affects the hardware a model needs, not how securely it is deployed. Smaller models are in fact easier to keep inside tightly controlled environments.

How do we report a security concern?

Use the contact page and mention security in your message. Reports are routed straight to our engineering team, and we keep you informed until the matter is resolved.

Bring your security team to the first call.

The best time for their questions is before anything is built. We will walk them through the architecture and leave them with answers in writing.