Trust

What our systems guarantee, and where those guarantees stop.

DSI sells consistency, provenance and controlled infrastructure. This page states the security architecture behind Pathiqa and Exostrate, the data flows they permit, and how their controls map to regulatory objectives.

Security architecture

Pathiqa · policy-mediated access

Agents declare intent, scope, and boundaries before touching data; the declaration becomes an enforceable contract. Raw data remains in its system of record unless an authorised task explicitly requires transmission, and Pathiqa mediates what is released, to whom, for what purpose and under which policy.

Exostrate · contained execution

Every agent runs inside an isolated, lease-bound runtime: default-deny networking, encrypted persistence, dropped capabilities, and hard budgets, enforced outside the agent’s control. Enforcement points fail closed; if a component is absent or lying, the boundary still holds.

One chokepoint for outbound access

Models, tools, and data are reached only through brokers. Provider keys are never exposed to the agent, token budgets cannot be exceeded, and data-loss-prevention redaction runs before anything leaves the boundary.

Audit-log integrity

Tamper-evident

Actions are written to a hash-chained, append-only ledger that detects tampering and reordering.

Replayable

Recorded execution can be replayed deterministically from captured prompts, model outputs and tool results.

Retention-aware

GDPR crypto-shredding removes personal data without breaking the chain.

Isolation & residency

Where data lives, and how strongly a deployment is isolated, is a deployment choice rather than a fixed property of the platform.

Hosted
A managed instance operated by DSI.
Dedicated
A single-tenant instance in a dedicated environment, for stricter isolation requirements.
On-premise
Installed inside the organisation’s own environment, for sovereign and high-sensitivity workloads.
Controls & standards mapping

Each mapping states the control objective a capability addresses, what DSI provides towards it, and what remains the customer’s responsibility.

DSI capabilityControl objectiveRelevant provisionWhat DSI providesCustomer responsibility
Pathiqa decision ledgerTraceability and event loggingEU AI Act Article 12Recorded agent actions, decisions and evidenceClassification of system, retention policy, operating controls
Human approval controlsHuman oversightEU AI Act Article 14Approval, intervention and stop controlsAppropriate oversight design, staffing and escalation
Third-party model mediationICT third-party risk supportDORAControlled model-provider access and policy enforcementVendor assessment, contracting and regulatory obligations

These mappings identify controls that may support an organisation’s compliance obligations. Use of DSI products does not itself establish regulatory compliance, certification or legal conformity.

Vulnerability reports

Found a security issue in our products or this site? We run a responsible disclosure process and read every report.

Responsible disclosure