Reframe
Security and Governance

One platform. One boundary. Yours.

One hard trust boundary. Reframe is the single governed layer across it, Microsoft-native, single tenant by construction. Your data never leaves your boundary, and every answer is grounded while every action is audited.

Single tenant
Your cloud boundary
Your keys
Your network
Query time
Access enforced

The Deployment

A dedicated, isolated environment inside your own tenant.

We stand up a hard trust boundary inside your tenant. Your keys, your network, access control enforced at query time. One boundary, and Reframe is the single governed layer across it.

Single tenant isolation

A dedicated environment per firm. No shared compute, no shared index, no co-mingled data. One tenant, one boundary.

Your keys, your network

Customer-managed keys and your own network controls. Reframe runs where your data already lives, under your Azure governance.

Enforced at query time

Permissions are evaluated on every request against your source-system ACLs. Answers only ever reflect what the asker may already see.

Microsoft-native, one governed layer

Built on the Microsoft cloud you already run, with Reframe as the single governed control plane across every model, tool, and action.

DMS Email Contracts Precedent ONTOLOGY Context Graph REFRAME GOVERNED LAYER Chat Search Word Agents YOUR TENANT READS QUERY TIME ACL CHECKED
Tools reach the graph only through the governed layer. Nothing crosses the boundary; the ACLs travel with every query.
Inside the Boundary

How deployment works in your tenant.

Every Reframe deployment is a dedicated, single tenant environment stood up inside your own Azure tenant. The boundary is dedicated to your firm, and everything below holds on day one.

Isolation

A dedicated environment, per firm

One enclave for one firm, provisioned inside your Azure tenant. No shared compute, no shared index, no co-mingled data.

Keys

Customer-held keys

Encryption keys stay in your hands, in your own key vault, under your rotation and revocation policies. Reframe operates under the access you grant.

Network

Private networking

The enclave runs on private endpoints inside your network perimeter. No public data plane, and no traffic your firewalls and monitoring cannot see.

Access

Enforced at query time, on every read and write

Permissions are evaluated on each request against your source-system ACLs, reads and writes alike. Nobody, human or agent, touches what they could not already open.

Audit

A complete audit trail of agent actions

Every model call, tool invocation, and agent step is recorded end to end, so any answer or action traces back to its source, its actor, and its approval.

Boundary

Data never leaves

Ingestion, indexing, storage, and inference all run inside the enclave. Your knowledge never crosses the boundary, at rest or in flight.

Models

Model calls stay inside the enclave

Inference runs against model endpoints deployed within the boundary. Prompts, context, and outputs never transit a shared or external service.

Training

No training on customer data

Your data is never used to train, tune, or evaluate shared models. What the firm knows stays the firm's alone.

Subprocessors
None with data access outside the enclave.

Every component that can touch firm data runs inside the boundary, under the same keys, the same network, and the same audit trail as the rest of the deployment.

Aligned by Design

The standards your risk committee already trusts.

The enclave is built to the frameworks your firm is measured against, so the controls are evidence, not a promise.

SOC 2 Type II
Trust services
ISO 27001
Infosec mgmt
NIST AI RMF
AI risk mgmt
AI
EU AI Act
Regulatory
ABA Model Rules
Professional
How Control Works

Governed retrieval, audited action, human in the loop.

Governance is not a policy binder. It is enforced in the path of every query and every action, inside the boundary, under one control plane.

ACL-aware retrieval

Retrieval honors the permissions of your source systems on every request. Nobody sees a document, clause, or matter they could not already open.

Audited agent actions

Every model call, tool invocation, and agent step is logged end to end, so each answer and action traces back to its source and its actor.

Human in the loop

Critical actions pause for review. Firm playbooks decide what an agent may do on its own and what must wait for an attorney to approve.

Data never leaves your boundary

Ingestion, indexing, and inference all run inside the enclave. Your knowledge is never used to train shared models and never crosses the boundary.

How It Maps

The Enclave keeps it yours.

Reframe is one system in three deliberate layers. Security is the middle layer, the deployment that holds the other two inside your boundary.

The Software

The Ontology

Holds the knowledge. Your firm structured into a per-tenant Context Graph, grounded to the source and permission aware.

The Deployment

The Secure Enclave

Keeps it yours. The single governed layer inside your tenant, your keys, your network, enforced at query time.

The Surface

Connected AI Tooling

Puts it to work. Chat, Search, the Word plugin, and Agent Workflows, every answer grounded and every action audited.

Get Started

One boundary. One governed layer. Yours.

The firms that cannot afford to guess have already stopped guessing.