Signed-in application and API flows
GAIA Civil enforces account authentication, secure password hashing (bcrypt), and cryptographically signed JWT access tokens for every API request.
GAIA Civil security and governance
GAIA Civil protects customer drawings, specifications, and commercial intelligence with tenant-isolated vector namespaces, AES-256 encryption at rest, network-disabled execution sandboxes, and contractually binding zero-training agreements governing ORION.
Production controls are backed by contractually enforced DPAs and verifiable cloud architecture.
Current implementation evidence
GAIA Civil’s multi-layered security model combines application-level tenant scoping, ephemeral ORION inference, encrypted cloud storage, and strict human decision boundaries.
GAIA Civil enforces account authentication, secure password hashing (bcrypt), and cryptographically signed JWT access tokens for every API request.
Every project document, extracted chunk, and embedding vector is bound to a verified tenant ID in PostgreSQL and stored in tenant-dedicated ChromaDB collections.
ORION operates inside GAIA Civil under enterprise AI agreements ensuring prompts, uploaded drawings, spec books, and generated reports are never used to train foundation models.
Agent review and calculation tasks execute within ephemeral Linux container sandboxes with network interfaces disabled and strict TTL limits.
A three-part security model
A secure feature can be undermined by the wrong environment or operating process. A contract can promise something the architecture does not deliver. GAIA Civil’s buyer review connects all three. Inspect our technical docs for detailed multi-tenant and API specifications.
Authentication, authorization checks, source traceability, review states, credential boundaries, and safe workflow behavior in the current implementation.
Google Cloud infrastructure, AES-256 storage, TLS 1.3 network path, Secret Manager, Cloud Logging, automated backups, and isolated vector namespaces.
Contractual zero model training, approved data use, retention/deletion schedules, geographic residency, SOC 2/ISO certifications, and incident SLAs.
Architecture review map
A comprehensive review map showing how customer data travels from authenticated client requests through containerized APIs, isolated vector indexes, and zero-training AI models.
Verify account lifecycle, authentication, assigned role, privileged access, and JWT signature verification.
Trace tenant, project, document, and action checks through every applicable API, vector namespace, and relational table.
Name the application containers, background workers, zero-training AI model endpoints, and network-disabled sandboxes.
Map uploaded PDF files, extracted text, vector embeddings, generated dossiers, backups, retention schedules, and deletion paths.
Confirm source-linked review, responsible human approval, authorized export destinations, and immutable audit logs.
Buyer security review
These are the core domains Pegasus reviews during technical customer onboarding to ensure compliance with enterprise IT and legal requirements.
Decision governance
GAIA Civil keeps ORION’s source locators, methodology log, report versions, needs-review states, and named human actions visible so an unexplained AI result cannot be presented as an approved engineering or commercial decision.
Security review path
The security review delivers verified architectural evidence, documented provider terms, and clear operating agreements.
Identify project document types, data classifications, user roles, and geographic requirements.
Document the proposed network path, tenant vector namespace, storage buckets, and deletion schedules.
Review SOC 2/ISO certifications, DPA terms, zero-training AI agreements, and RTO/RPO SLAs.
Sign mutual agreements, configure tenant security policies, and initiate secure user provisioning.
Security FAQ
Clear technical specifications regarding data encryption, residency, AI model policies, and disaster recovery.
No. ORION operates under enterprise commercial agreements that contractually prohibit customer data from being used to train or fine-tune public foundation models. Approved context is processed for inference under zero-training terms; GAIA Civil retains tenant-scoped source files, artifacts, reports, and audit records only according to the configured customer lifecycle and deletion policy.
Primary compute and storage reside on Google Cloud Platform within United States regional clusters (such as us-central1 Iowa, us-east4 Virginia, and us-west1 Oregon). Optional regional pinning for the European Union (europe-west3 Frankfurt) and the UK is available under enterprise service agreements.
GAIA Civil enforces mandatory TLS 1.3 / HTTPS encryption in transit for all client-to-server and inter-service communications. At rest, all relational databases (PostgreSQL), object storage buckets (GCS), and vector database volumes are encrypted using industry-standard AES-256 bit encryption.
Data isolation is enforced at every architectural layer: cryptographically signed JWTs embed tenant_id on all incoming API requests; relational database queries enforce tenant scoping via PostgreSQL indexed constraints; and vector embeddings are partitioned into tenant-dedicated ChromaDB namespaces.
When agents perform specialized data extraction or calculation verification, they run in isolated, ephemeral Linux sandboxes with network interfaces disabled. Sandboxes only receive curated document snippets beneath /workspace/evidence and have strict time-to-live (TTL) limits, preventing unauthorized network calls.
GAIA Civil maintains a tiered Business Continuity and Disaster Recovery posture: Stateless API services achieve RTO < 15 minutes / RPO = 0 minutes; managed PostgreSQL databases achieve RTO < 1 hour / RPO < 5 minutes via continuous Write-Ahead Logging (WAL); object storage achieves RTO < 30 minutes; and vector indexes achieve RTO < 2 hours via automated re-indexing.
The product workflow keeps source locators, assumptions, uncertainty, methodology updates, needs-review states, and responsible human actions visible. Final technical, estimating, engineering, and commercial decisions remain with qualified people.
Bring your data classification guidelines, required deployment and residency boundaries, identity/SSO requirements, user roles, retention schedules, provider restrictions, and compliance questionnaires. We will walk through the complete data path with your security team.
Plan the security review
Start with data classification, identity, residency, retention, provider, integration, and legal requirements so the evaluation is grounded from day one.