Trust isn't a feature.
It's the foundation.
mploi was designed for organizations where data sovereignty and auditability are not negotiable. Every architectural decision starts with this constraint.
Guardrails in action — live
Four non-negotiable principles
The principles your security and compliance teams will recognize on day one.
Data Sovereignty
mploi runs entirely on your infrastructure — on-premises, in your private cloud, or in air-gapped environments. There is no SaaS backplane, no analytics phone-home, no required external dependency. Your data, your conversations, your audit logs, and your model traffic stay inside the boundary you draw.
Deterministic Execution
Security is enforced by the platform, not by prompt instructions. When an agent isn't permitted to invoke a tool, the platform blocks the invocation — regardless of what the model decides. Permissions, tool access, and data scoping are concrete, testable, and auditable.
Complete Transparency
Every conversation, every tool invocation, every authentication event, and every administrative change is recorded in a structured activity log. Your security team can answer "what did this agent do, on whose behalf, with what data?" — exhaustively, for any moment in the system's history.
Model Portability
mploi is not built around any single AI provider. Switch models per-agent at any time, run open-source models on your own GPUs, or restrict regulated workloads to private inference. You retain leverage; you avoid vendor lock-in.
The controls your auditors will ask about
Every box on the security questionnaire — answered in the platform, on day one.
Single sign-on & group-based access control
Integrate with your existing identity provider — Azure Entra ID, Okta, Google Workspace, Keycloak, or any standards-compliant OIDC source. Users sign in with the credentials they already have, with the same MFA and conditional-access policies their other tools enforce.
Every primary object in the platform — agents, tools, knowledge sources, MCP servers, dashboards — has its own group-based access control. Your finance agents stay invisible to marketing. Your production database tool stays invisible to interns. Granularity is per object.
Sensitive data never reaches the model
Built-in pattern recognition automatically detects and masks dozens of categories of sensitive data — SSNs, credit cards, API keys, email addresses, phone numbers, IP addresses, internal identifiers — before any model sees them. Add custom regex patterns for organization-specific identifiers in minutes.
Masking is transparent: the model sees opaque tokens; original values are restored only on the way back to the authorized user. And when an agent needs credentials to act, they're collected in a secure side channel that passes them straight to the tool — never through the model. Compliance gets a clear answer to "did the AI ever see this PII?" — with the audit log to prove it.
Hard boundaries on what agents can do
Tool permissions are enforced at the platform layer — independent of the model's reasoning. If an agent isn't authorized to query production, the query never reaches production. No prompt injection can change that. No clever rephrasing gets around it.
Require human confirmation for any destructive operation — and when a human says no, the denial (with their reason) becomes part of the record, as in the run shown here. Plan mode forces the agent to draft a proposal before executing. Every invocation is recorded with exact arguments, result, timestamp, and the identity that authorized it.
Answer "what happened?" definitively, for any window
Activity logs capture every action: user authentications, configuration changes, agent runs, individual tool invocations, document uploads, permission edits. Each entry is structured, queryable, and exportable.
The token usage of every model call is captured. The full conversational context is retained per-session. Compliance reviewers can reconstruct the complete history of any interaction — what was asked, what the agent did, what data it touched, and what was returned.
Designed to pass your compliance review
A quick checklist of the controls your security team will look for.
Deployment that fits your risk profile
mploi is the same product across deployment models. Pick what your security posture requires.
Want the full
security briefing?
Our team is happy to walk your security and compliance leadership through the platform's controls in detail.
Request a Security Briefing