Astryastry

Privileged stays privileged.

Legal teams cannot put privileged material into a tool that might surface it to the wrong person. Astry enforces access physically, cites a source on every answer, and journals every request, so confidentiality is the architecture, not a promise.

Atlas project update
Give me a summary of where the Atlas project stands and what was decided at the last meeting.
Write a message…

Astry answers only from what you are cleared to see.

A cited source on every answer

Confidentiality is the architecture.

Privilege is not a setting you toggle. It is enforced by where files can and cannot go.

Privilege preserved

Privileged material is walled off by construction. The model only ever sees the matter the asker is cleared for.
Inside the Trust Layer

A cited source on every answer

Each answer carries the exact memo, email or filing it came from. Open the original in one click.
How Ask works

Full audit trail per request

Every query, every file read and every response lands in an append-only log that cannot be edited or deleted.
See the audit log

Walled by matter

Access inherits from your source systems. A matter you cannot open stays absent from every answer.
Access control

Absent, not hidden

Files outside the matter are never copied into the request. The model cannot cite, reference, or even discover a document it was not given.

Runs in your cloud

Astry deploys inside your own Azure, GCP or AWS. We hold no credentials to your environment.
How BYOC works

How privilege is kept.

Five steps, on every request. No override, no exception.

  • 01

    Clearance by matter

    Before anything runs, Astry resolves which matters the asker may open, straight from your source systems.

  • 02

    Physical projection per request

    Only the cleared files are copied into a per-request sandbox. The model runs with that directory as its entire world, then the sandbox is destroyed.

  • 03

    Cited answers

    The response is built from those files alone and lists each one. No source means no claim.

  • 04

    Append-only audit

    The query, the files read and the answer are journaled to a log that cannot be edited or deleted.

  • 05

    Erasure on request (GDPR Art. 17)

    Remove a matter and Astry's departure-kit tooling documents what was retrieved and erased, so you can answer a deletion request with a record.

Good to know.

  • Access is enforced at the filesystem level, not by a prompt. Before inference Astry copies only the files the asker is cleared to see into a throwaway per-request sandbox, runs the model with that directory as its world, then deletes it. A file outside the matter is physically absent, so no prompt can reach it.

Confidentiality as architecture.

See how Astry keeps privileged work privileged, in your own cloud.