The controls, where they apply, what we will put in a contract, and exactly where each claim stops. Most AI vendors answer this with a logo wall. This is the actual posture.
Not add-ons and not an enterprise tier. This is how the systems are built in the first place. Pick one to see how it works.
Your prompts and completions are not retained by us or by the model providers we route to. Retention is switched off at the API level, not left to a policy promise.
Chosen by your security team, not for our convenience. The same product in each, with the line drawn where you need it. Switch between them to see what crosses it.
We deploy into your AWS, Azure or GCP tenancy. You own the infrastructure, the keys and the bill; we hold time-boxed access that your team can revoke.
Deployable in India, UAE or US regions. The region is written into the contract rather than set in a console, so it cannot drift after the review is signed off.
India region
Designed to support DPDP Act obligations
For teams whose data must stay in India. Retention windows and erasure handling are written into the contract and reviewed with your counsel.
Stays in the region
Where a model provider has no in-region endpoint for what you need, we say so before contract, and you choose: a self-hosted model, or the transfer under agreed terms.
Procurement is where most AI pilots stall. Here is what we hand over and when, so your security review can start before the contract does.
Data processing agreement
Our standard DPA, or yours if you would rather work from your own.
With the contractSecurity questionnaire
We complete yours rather than sending back a PDF. No length limit.
5 working daysPenetration testing
A third-party test is commissioned before go-live on every production deployment, and its summary shared under NDA.
Before go-liveRetention and residency terms
Region pinning and retention windows written into the contract, not set in a console.
With the contractNamed subprocessor list
Every model provider and service in the path, with notice before any change.
On requestAll of it, under NDA, before a contract exists
Send your questionnaire to astrylx.official@gmail.com and the clock starts that day.
A logo wall implies a certificate. Where we hold one, we will show it. Where we do not, the wording says so.
Our security practices are modelled on the Trust Services Criteria. We have not been audited, and we will say so on a call rather than let a logo imply otherwise.
The last column is empty on purpose. We are an early team and have not been through an independent audit. No certification is held or claimed, and we will say the same on a call.
The short answers. The long ones belong in your questionnaire, and we would rather write them there.
No. Our practices are modelled on both, and we have not been audited, so no certificate is held or claimed. We would rather say that plainly than let a badge suggest otherwise. If a certificate is a hard requirement for you, tell us early and we will tell you where we stand.
Bring one process you think an agent could run.
We'll tell you straight whether it's worth building — and what it would cost if it is.