What our systems guarantee, and where those guarantees stop.
DSI sells consistency, provenance and controlled infrastructure. This page states the security architecture behind Pathiqa and Exostrate, the data flows they permit, and how their controls map to regulatory objectives.
Pathiqa · policy-mediated access
Agents declare intent, scope, and boundaries before touching data; the declaration becomes an enforceable contract. Raw data remains in its system of record unless an authorised task explicitly requires transmission, and Pathiqa mediates what is released, to whom, for what purpose and under which policy.
Exostrate · contained execution
Every agent runs inside an isolated, lease-bound runtime: default-deny networking, encrypted persistence, dropped capabilities, and hard budgets, enforced outside the agent’s control. Enforcement points fail closed; if a component is absent or lying, the boundary still holds.
One chokepoint for outbound access
Models, tools, and data are reached only through brokers. Provider keys are never exposed to the agent, token budgets cannot be exceeded, and data-loss-prevention redaction runs before anything leaves the boundary.
Tamper-evident
Actions are written to a hash-chained, append-only ledger that detects tampering and reordering.
Replayable
Recorded execution can be replayed deterministically from captured prompts, model outputs and tool results.
Retention-aware
GDPR crypto-shredding removes personal data without breaking the chain.
Where data lives, and how strongly a deployment is isolated, is a deployment choice rather than a fixed property of the platform.
- Hosted
- A managed instance operated by DSI.
- Dedicated
- A single-tenant instance in a dedicated environment, for stricter isolation requirements.
- On-premise
- Installed inside the organisation’s own environment, for sovereign and high-sensitivity workloads.
Each mapping states the control objective a capability addresses, what DSI provides towards it, and what remains the customer’s responsibility.
These mappings identify controls that may support an organisation’s compliance obligations. Use of DSI products does not itself establish regulatory compliance, certification or legal conformity.
Found a security issue in our products or this site? We run a responsible disclosure process and read every report.