Skip to main content
تقرير الأمان والامتثال

أمان بمستوى مصرفي مع انعدام حفظ الأوامر

بوابة الذكاء الاصطناعي متعددة المزودين وجسر AWS Bedrock SigV4 (BYOK) مصممة للامتثال لمعايير HIPAA و SOC 2 Type II و GDPR مع مسح الذاكرة المتطايرة فور اكتمال البث.

Zero-Prompt Persistence

Volatile RAM Ring Buffers

All prompt tokens and streaming completions are temporarily stored in ephemeral in-memory ring buffers inside AWS ECS Fargate micro-VMs. As soon as the downstream HTTP connection closes or stream EOF is reached, the memory allocated for the transaction is cryptographically zeroed out (`memset_s`). No prompt data is ever written to swap, local NVMe, EBS volumes, or cold disk.

AWS KMS Envelope Encryption

Customer Master Keys (CMKs)

Tenant API credentials and configuration payloads are protected using AWS KMS Envelope Encryption. The KMS Customer Master Key (CMK) never leaves the AWS KMS Hardware Security Module (HSM). Ephemeral Data Encryption Keys (DEKs) are generated per request, used strictly in memory, and discarded immediately.

TLS 1.3 Strict Forward Secrecy

End-to-End Cryptographic Ingress

All traffic traversing CloudFront Anycast and the ECS Fargate ingress layer requires TLS 1.3 with ECDHE (Elliptic Curve Diffie-Hellman Ephemeral) key exchange and AES-256-GCM / ChaCha20-Poly1305 ciphers. Deprecated SSL/TLS 1.0, 1.1, and 1.2 CBC suites are rejected at the edge.

Tenant-Isolated pgvector Partitions

Row-Level Security (RLS)

Vector embeddings stored in Amazon Aurora Serverless represent mathematical cosine distance coordinates generated by Amazon Titan Embeddings v2. Embeddings are partition-isolated per tenant with PostgreSQL Row-Level Security (RLS) enforcement, ensuring cross-tenant vector contamination is mathematically impossible.

Enterprise Compliance Alignments

Audited against stringent healthcare, enterprise security, and international data privacy benchmarks.

Framework / StandardScopeCompliance StatusArchitectural Safeguards
HIPAA Security Rule & BAABusiness Associate AgreementFully CompatibleSupports BAA execution for healthcare workloads. Zero-Prompt Persistence guarantees Protected Health Information (PHI) is never stored at rest, and in-flight PII masking provides automated scrubbing before relay.
SOC2 Type II Trust PrinciplesSecurity, Availability, ConfidentialityAudit AlignedArchitecture adheres directly to SOC2 Type II trust service criteria. Continuous telemetry logging of gateway operations without recording prompt/completion payload bodies.
GDPR Article 28Data Processor ComplianceEU Processor ReadyServes as an encrypted, stateless data processor. Because prompt content is not retained on disk or used for LLM foundation model training, GDPR right-to-erasure requirements are satisfied by design.
Need a Custom BAA or Third-Party Pen-Test Report?

Our security engineering team provides architecture reviews and BAA execution for enterprise cohorts.

security@kiyaslabs.tech
التوزيع السحابي والحدود الأمنية

عزل كامل داخل بيئة VPC المخصصة

Tier 1< 2ms Ingress

CloudFront Anycast Edge

Global edge presence terminating TLS 1.3 with strict forward secrecy ciphers. Provides automated AWS Shield DDoS mitigation and intelligent regional routing to nearest compute.

  • TLS 1.3 Strict Forward Secrecy
  • Global Anycast Geo-Routing
  • AWS Shield Standard DDoS Mitigation
  • HTTP/2 & HTTP/3 multiplexing
Tier 2< 0.5ms Relay

ECS Fargate Relay Engine

Containerized relay workers operating entirely in volatile memory. Converts Bearer tokens to AWS SigV4 HMAC-SHA256 signatures and tees SSE streaming tokens to background workers.

  • AWS SigV4 in-memory translation
  • Asynchronous stream-teeing engine
  • Volatile RAM ring buffers (zero disk)
  • Per-tenant token FinOps rate limiting
Tier 3< 2ms Vector Search

Aurora pgvector & KMS Vault

Amazon Aurora Serverless PostgreSQL with pgvector HNSW indexing for high-speed semantic matching. Provider API keys are decrypted via AWS KMS envelope encryption exclusively in volatile RAM.

  • Amazon Titan Embeddings v2
  • Aurora pgvector HNSW cosine search
  • AWS KMS Envelope Key Encryption
  • Tenant-isolated row-level partitions
فحص الامتثال

طلب شهادات الأمان واتفاقية معالجة البيانات

Direct Technical Lead Inquiry

Dedicated Routing Channels

Enterprise Sandbox

enterprise@kiyaslabs.tech

Provisioning for enterprise subscriptions, dedicated VPC relays, and HIPAA BAAs.

Developer Support

support@kiyaslabs.tech

Inquiries regarding the AWS SigV4 translation bridge, OpenAI SDK drop-in, or stream-teeing.

Security Disclosures

security@kiyaslabs.tech

Encrypted PGP channel for vulnerability reporting, pen-test reports, and compliance reviews.

Kiyas Labs Technologies

Operating Entity for PromptRelay™ • Response SLA: Within 1 Business Day