Every query, on the record.
Persistent audit rows for every prompt, retrieval, latency tick and trace ID. CSV exportable audit log. Retained 90 days by default; Enterprise deployments can archive to immutable/WORM storage.
The AI your auditor will love. private·ai is a compliance-first assistant for regulated teams. Every retrieval is logged, every answer is grounded, every span is traceable — runs inside your approved deployment boundary.
Six capabilities, working as one system — so your team can ship AI without making your CISO file a JIRA ticket.
Persistent audit rows for every prompt, retrieval, latency tick and trace ID. CSV exportable audit log. Retained 90 days by default; Enterprise deployments can archive to immutable/WORM storage.
Input guard blocks injections and blocked terms. Content filter scrubs PII from retrieved chunks. Output filter checks for hallucinated PII and bounded length.
Dense vector similarity combined with sparse BM25 ranking, fused with RRF and reranked. Better recall, better grounding, fewer hallucinated answers.
Full distributed tracing via OTEL spans, shipped to Jaeger. See where latency lives, why a retrieval missed, and which model answered.
Every assertion is anchored to the source chunk and page. When the corpus is silent, the model says so — instead of inventing a plausible lie.
Runs inside your deployment boundary. Local Ollama for inference, Qdrant for vectors, Postgres for audit. Hybrid and cloud modes available. No API keys to a third party in local mode.
Click a question to see the assistant retrieve, ground, and cite — in real time.
Seven discrete stages, every one observable and overridable. Hover a stage to see what it does.
Dense vector similarity (Qdrant) + sparse BM25, fused with reciprocal rank.
Each guard runs as a separate, audited stage — so an incident report can tell you exactly where (and why) something was caught.
Sanitizes every prompt before it enters the pipeline. Detects injection patterns, blocked terms, and obvious exfiltration attempts.
Scrubs PII from retrieved chunks before they reach the LLM context. Names, emails, account numbers — redacted in flight.
Final check on the generated response. Detects hallucinated PII, enforces length bounds, and verifies citation presence.
Persistent rows in Postgres for every query, retrieval, guard decision, model call, latency tick, feedback and admin action — joined by a single trace ID.
When your auditor asks "prove that no PII was exposed last Tuesday", you don't open a slack thread. You run a query.
OpenTelemetry spans for every stage — from the auth check to the OTEL export itself. Ship to Jaeger, Tempo, Honeycomb, or your own stack.
"Show me that no PII was exposed in any response last quarter."
† Cloud LLM positioning generalized from the top three vendors as of Q2 2026. Your mileage may vary; your auditor's tolerance will not.
We had a six-month internal audit on AI use. private·ai's trace export answered every question on the agenda before the auditor even sat down.
The content filter alone justified the contract. Watching PII get scrubbed out of retrieval in flight is the kind of thing security teams cry about.
It does the unglamorous thing well: when the answer isn't in our docs, it says so. We stopped getting confidently-wrong responses overnight.
No per-token surprises. You run the iron — we license the system that keeps it audit-clean.
Prove the value on your own data before committing.
Production deployment for a single business unit.
Multi-tenant, multi-region, your CISO's checklist — covered.
Eight of them, anyway. Email info@safe4ai.com for the other forty.