What your security team can ask for, and how.
Exalt Reserve
What Exalt states about Exalt Reserve, on one page, and how your security team asks for the rest.
What we state
- Where
- Your own AWS, Azure, or Google Cloud account. This is not an Exalt-hosted shared service.
- Exalt
- A management plane outside your account. It holds no customer content.
- Inside
- Models, retrieval, agents, and monitoring, in your account.
- Models
- Open models, self-hosted by default: Llama, Mistral, Qwen, Gemma, and DeepSeek. Any outside AI service is decided with you, per use case.
- Network
- Your private network only. No public endpoint.
- Sign-in
- Your identity provider: Microsoft, Okta, or Google.
- Access
- Roles set by your admin. Search respects the permissions set on source documents.
- Audit
- Questions, answers, sources shown and admin actions, with who and when, kept in your account. A role you choose exports the log.
- History
- Your admin sets how long prompts and answers are kept, and can delete them.
- API
- Your own applications can call Exalt Reserve through an API.
- Data
- Data is encrypted at rest and in transit.
- Yours
- Data, models, vector stores, and credentials stay in your environment.
- Policy
- Network, identity, and access policy stay under your control.
- Billing
- Exalt bills for its software. You pay your cloud provider directly for the infrastructure.
How the install is packaged, encryption keys, and regions are available to your security team on request.
The detail behind each line
- How it runsWhat sits in your account, and the one part Exalt runs outside it.
- ModelsThe five open model families, self-hosted.
- Private accessPrivate network, then your identity provider.
- Audit logWhat is recorded, where it is kept, and who exports it.
- Cloud billExalt's bill and your own cloud bill.
- Common questionsThe questions reviewers ask, answered from this record.
Bring your security team.
Ask for a security review when you book a consultation. Bring the questions your team needs answered.