Enterprise-grade security, by default

Twala is built from the ground up with encryption, strict data isolation, and AI infrastructure that keeps everything inside a private network.
Your data never reaches a
third-party AI provider
Most AI platforms forward your documents to external LLM APIs over the public internet. Twala is different. All AI inference, including the large language models that read and reason over your documents, runs inside a dedicated private network. Your data never traverses the public internet to reach an AI model. It stays inside the same private environment from upload to response.
LLM inference runs inside a private VPC with no public internet routing
AI models are hosted and accessed via private network endpoints, not public APIs
Documents are embedded and indexed within the same private environment
Zero document content transmitted to external AI providers or third parties
How we protect your document
Hashproof Technology™ | Cryptographic assurance, engineered for enterprise trust
Public Key Infrastructure
Cryptography
TLS 1.3
AES-256
X.509
Blockchain Timestamping
Chained Anchoring
How we protect your data
Six security controls built into every layer of the platform
Encryption at rest and in transit
Protected storage, secure transport, and trusted authentication.
Workspace-level data isolation
Each workspace is isolated with no cross-access to data or AI context.
SSO and enterprise authentication
Full-stack security with encrypted data and secure tokens.
Role-based access control (RBAC)
Define granular access control for every workspace and asset.
Rate limiting and abuse prevention
Prevent abuse with rate limits and full request traceability.
User-controlled document indexing
Separate storage-only files from AI-indexed documents.
Infrastructure and architecture
Private cloud infrastructure with AI inference running entirely within an isolated network.
Private cloud infrastructure
All services run inside a dedicated private VPC
Encrypted object storage with IAM-authenticated access
Vector search index isolated per workspace namespace
In-memory cache and job queues for async processing
AI inference stays private
All inference stays within a private VPC for secure processing.
AI models are hosted and accessed via private network endpoints only
Your documents are never sent to third-party LLM providers
Embedding generation stays within the same private environment
Observability and audit
Structured JSON logging with correlation IDs on every request
Response timing headers for latency monitoring
Immutable document version history and annotation snapshots
Consistent error envelope format for integration reliability
Resilient architecture
Built for high availability with fault-tolerant service design
Modular services that scale independently under load
Graceful error recovery so failures never cascade to user
Background processing keeps the platform responsive under heavy load.
Security checklist
Every security measure active on every account, on every plan.
AI inference stays private
AI inference runs inside a private VPC with no public internet routing
No data sent to third-party LLM providers
Workspace-level namespace isolation at infrastructure level
SHA-256 hashed refresh token storage
Http Only secure cookies with SameSite protection
Short-lived JWT access tokens (15-minute expiry)
Refresh token rotation and immediate prior-token invalidation
Fixed-window rate limiting on all endpoints
RBAC with per-request authorization middleware
SSO via SAML 2.0 and OpenID Connect for enterprise identity providers
Correlation ID on every request for full traceability
User-controlled document indexing: opt in or out per file
Automated session expiry and forced re-authentication

Questions about security?

Reach out and we'll walk you through our security architecture in detail.
Try it free
Questions about security?
Reach out and we'll walk you through our security architecture in detail.