Skip to content
LSTRAN

Security & responsibility

Control belongs
in the design.

Before a system acts, its boundaries need to be clear: the information it can access, the tools it can use and the decisions a person must approve.

Nothing goes around it

Four of these five transfers carry a rule and are allowed. The fifth one does not carry one, so it stops at the checkpoint. The transfer never happens — but the attempt itself is recorded.

Record · from → to · route · under which rule

  • 01AI employee → BrainRULE-01 · allowed
  • 02AI employee → AI modelRULE-02 · allowed
  • 03Gate → AI employeeRULE-03 · allowed
  • 04AI employee → AI employeeRULE-04 · allowed
  • 05AI employee → The outside worldno rule · blocked

Design principles

How the boundaries are built.

Isolation

Your installation is yours alone.

Every company runs its own isolated installation of Matrix — its own environment, its own database, its own storage. Isolation is enforced at the infrastructure level, not by application logic. Even companies in the same group are separated. Data stays in the EU, encrypted in transit, at rest — and while being processed. There are no public entry points, and no remote commands lead from us into your installation.

Identity

People sign in. AI employees don’t.

People authenticate through your company’s standard corporate identity. AI employees are not users: each one has its own narrowly scoped system identity, access only to what its role requires, and no administrative rights — ever. Mixing the two would invite treating an AI employee as “a cheap user account”. We designed the model so that can’t happen.

Controlled communication

Nothing speaks for itself.

Every transfer inside Matrix is typed and carries its rule: who is sending, to whom, what kind of content, under which permission. Checkpoints apply to all traffic — including every exchange with AI models. Allowed transfers are recorded; blocked attempts are recorded too. No component talks to the outside world on its own.

Quarantined connections

The outside world stays outside.

Every connector to an external system is single-purpose and quarantined: it runs isolated from the core, has no access to internal data — not even read access — and receives only the payload of its current task. Its only channel leads through the Security Grid, which validates traffic in both directions. If a connector is ever compromised, the blast radius is one isolated box, not your company’s knowledge.

Secrets

Credentials no one can read.

Access credentials live outside the reach of AI employees and users alike. Sensitive values are write-only: the system can use them, but no interface — not even administration — can display them back. Moving an AI employee between installations never carries secrets in the open; the preferred path is to issue fresh credentials at the destination.

Human oversight

Approval scales with consequence.

Controls are enforced by the platform, never by the component being controlled. Routine work flows freely; consequential actions — payments, commitments, outbound communication — require independent review; irreversible decisions stay with a person. A human decision never silently becomes a standing rule, and every new AI employee is activated by a person.

The starting point

Explicit boundaries.

01

Data and environment.

Agree where information is processed and stored, which services are involved and who operates the environment.

02

Identity and access.

Define permissions for people, software roles and system connections.

03

Review and evidence.

Identify consequential actions and agree how they are approved and recorded.

Software delivery

Fit the programme.

Within a larger software programme, we agree architecture, security requirements, review processes and acceptance criteria with the delivery partner.

The engagement makes responsibilities and permitted environments clear before development begins.

Technical review

Discuss the specifics.

Bring your requirements for deployment, data flows, model providers, retention, access, incident handling and audit evidence. We address them against the proposed implementation.

Detailed product specifications and security documentation are confirmed as part of the technical discussion.

Explore Security Grid

Build with Elstran

Make intelligence
part of your business.

Put Matrix to work in your company, or bring us into a software project. Start with the outcome you need.

Let’s talk