Skip to main content
Exalt Reserve

What your security team can ask for, and how.

Exalt Reserve

What Exalt states about Exalt Reserve, on one page, and how your security team asks for the rest.

What we state

Where
Your own AWS, Azure, or Google Cloud account. This is not an Exalt-hosted shared service.
Exalt
A management plane outside your account. It holds no customer content.
Inside
Models, retrieval, agents, and monitoring, in your account.
Models
Open models, self-hosted by default: Llama, Mistral, Qwen, Gemma, and DeepSeek. Any outside AI service is decided with you, per use case.
Network
Your private network only. No public endpoint.
Sign-in
Your identity provider: Microsoft, Okta, or Google.
Access
Roles set by your admin. Search respects the permissions set on source documents.
Audit
Questions, answers, sources shown and admin actions, with who and when, kept in your account. A role you choose exports the log.
History
Your admin sets how long prompts and answers are kept, and can delete them.
API
Your own applications can call Exalt Reserve through an API.
Data
Data is encrypted at rest and in transit.
Yours
Data, models, vector stores, and credentials stay in your environment.
Policy
Network, identity, and access policy stay under your control.
Billing
Exalt bills for its software. You pay your cloud provider directly for the infrastructure.

How the install is packaged, encryption keys, and regions are available to your security team on request.

Bring your security team.

Ask for a security review when you book a consultation. Bring the questions your team needs answered.