Send your architecture team this page. It covers the model we build for you and, separately, the platform you can deploy alongside it, answers what they are going to ask anyway, and says plainly where our answer is we do not claim that.
Start here, because this is what most people are reviewing us for. During a Foundry engagement we handle your training corpus, which is usually the most sensitive data you hold, and the controls below are enforced by the runner rather than by a clause in a contract. The second half of this page covers Bonacci Studio, which is a separate product you may not be buying at all.
The guardrails on a training run are a file your team reads before anything starts, not a paragraph we wrote about ourselves. A run that violates one is refused rather than flagged.
# the guardrails your reviewer reads guardrails: no_egress: true max_spend_usd: 8000 max_wallclock_hours: 72 placement: # blank provider = registered machines only. # nothing here can create infrastructure. provider: null region: eu-west-1 corpus: pii_scrub: true dedup: true claims: delivery_terms: owned_outright
This half applies to Bonacci Studio, the optional platform. A delivered model does not require it and nothing in this section applies to a Foundry engagement on its own. Studio runs on hardware you own, inside a boundary you already defend. Your firewall rules are the enforcement, and nothing here depends on trusting a promise we made in a questionnaire.
You do not have to take the paragraph above on trust. This is the real on-premise configuration, and your team can read every line of it before anything runs.
# the real config. no hidden endpoints. deployment.mode=onprem # inference points at your box, not ours OPENAI_BASE_URL=http://localhost:11434/v1 # ollama # no billing calls, no licence server razorpay.enabled=false paddle.enabled=false # your directory, your mail, your storage LDAP_ENABLED=true MAIL_HOST=smtp.internal
We do not hold SOC 2, ISO 27001, or HIPAA attestation, and we will not tell you otherwise to get through a procurement gate. We are a small company in Hyderabad. When we have an audit, it will be on this page with the report date.
We also do not publish an uptime SLA for self-hosted deployments, because we do not run them. Availability is your infrastructure. What we do commit to in the licence is a named support engineer and an agreed response time.
If your process requires a certified vendor, we are the wrong supplier today and we would rather say so now than in month four of a procurement cycle. If your process cares about where the data physically sits and who can reach it, keep reading, because that is the part we are built for.
We will walk your architecture and security reviewers through the guardrails on a training run, the job specification, the network boundary, and, if Studio is in scope, the compose file and the licence mechanism. Then we answer the questions this page did not. Bring the questionnaire if you have one.