Skip to main content
DSX Digital
Security & Enterprise Architecture

Enterprise AI, deployed inside your control boundary.

DSX Digital is built for organizations that handle sensitive documents, regulated data and business-critical AI workflows. DSX Guard, DSX Insight and DSX IQ can be deployed in your private cloud or on-premises, with enterprise policy, access control, auditability and human oversight designed into the architecture.

Every managed path to AI is governed before data reaches a model. Every document-derived decision can be traced to its source. Every answer across enterprise knowledge respects the permissions of the person asking.

Private cloudOn-premisesCustomer-controlled model accessAuditable by design
Request a Demo
The shared foundation

One security standard across all three products.

Security is not a separate feature added after deployment. It is the shared foundation underneath DSX Guard, DSX Insight and DSX IQ.

DSX Guard

Governs every managed path to AI — employees, applications and agents — under one policy set, and records what happened.

DSX Insight

Keeps source references, confidence scores, review decisions and process history attached to every document-derived output.

DSX IQ

Indexes the estate in place, retrieves only what the person asking may see, and cites the document, page and passage behind every answer.

One policy foundation. One audit standard. Three independently deployable products.

Data protection

Protect sensitive data before it reaches an external model.

DSX Guard evaluates managed AI requests before they leave your controlled environment. Values defined as sensitive by your organization can be masked, blocked, allowed or logged according to policy.

Detect

Identify personal, financial, health, commercial and technical information using built-in and organization-specific definitions.

Protect

Replace protected values with structured placeholders before an external model receives the request. Files and attachments are inspected under the same policy.

Restore

The mapping remains inside your controlled environment. When an approved answer returns, authorized values are restored before the response reaches the user.

External providers receive only the content permitted by your policy — not the original protected values.

Explore DSX Guard
Identity and access

Identity, permissions and separation.

Access to DSX products is governed by enterprise roles, product permissions and source-system entitlements, integrated with the identity provider your organization already runs.

Enterprise identity

Integrate DSX Digital with your enterprise identity provider through SAML 2.0 or OpenID Connect. Existing authentication policies — including multi-factor authentication — remain centrally enforced.

SAML 2.0 and OpenID Connect SSOEnterprise MFA enforcementCentralized authentication policiesSession and access controls

User lifecycle management

Automate user and group provisioning through SCIM so access reflects changes in the enterprise directory.

Automated user provisioning and deprovisioningGroup-based access assignmentCentral user-lifecycle managementRemoval of access when employment or responsibilities change

Role-based access control

Separate administrative, operational, review and standard-user responsibilities across DSX Guard, DSX Insight and DSX IQ.

User, reviewer and administrator rolesGroup- and workspace-level authorizationSeparation of administrative and operational dutiesProduct-specific permissionsSource-system access controls enforced at query timeControlled visibility for documents, extracted fields, policies and audit records

DSX IQ does not grant access to a document simply because a user asks about it. An answer is assembled only from sources that the requesting user is authorized to access.

Source data

No source migration. Your documents stay where they are.

DSX IQ connects to approved file servers and enterprise repositories using controlled, read-only access. Source documents remain in the systems your organization already manages.

Within your controlled environment, IQ creates a derived, permission-aware index for retrieval and whole-corpus reasoning beyond a single context window. Folder structure, document metadata, source location and access permissions remain part of the evidence behind each answer.

Read-only source connectionsDifference-only scheduled re-indexingPermission synchronization from the sourceDeleted-source removal at the next configured synchronizationCited answers linked to document, page and passageFull question, answer and source audit history
Explore DSX IQ
Document evidence

Document decisions that survive review.

DSX Insight preserves the evidence behind document processing from intake to system update.

Classification confidence for every documentSource and confidence attached to extracted fieldsValidation against enterprise rules and systemsConfigurable thresholds for human reviewRecorded exceptions, approvals and overridesTraceable workflow and integration historyAPI and webhook delivery to systems of record

Low-confidence output is routed for review rather than silently accepted. What was extracted, what passed validation, what failed and who approved the result remain available as part of the process record.

Explore DSX Insight
Deployment

Deployment inside your security boundary.

DSX Guard, DSX Insight and DSX IQ are deployed within an environment controlled by the customer. Choose private cloud or on-premises according to your data-residency, infrastructure, model-access and operating requirements.

Private cloudOn-premises
Deployment locationDeployed within the customer's private-cloud environmentDeployed within the customer's data center or controlled on-premises infrastructure
Data boundaryCustomer data, indexes, mappings and audit records remain inside the customer-controlled cloud boundaryCustomer data, indexes, mappings and audit records remain inside the customer-controlled on-premises boundary
Model accessCustomer-hosted models or customer-approved external model providersLocal models or customer-approved external model providers
Infrastructure and computeProvided and controlled by the customer within its private-cloud environmentProvided and controlled by the customer within its own infrastructure

Everything else follows your controls rather than the shape of the deployment: sensitive-data protection, identity and access, encryption and key management, logging and retention, monitoring integration, availability and recovery, change management and the division of operating responsibility are set the same way in both models and are covered below.

Customer-controlled model usage

Where customer-hosted local models are used, DSX Digital does not charge a separate model-usage fee. Infrastructure, compute capacity and model licensing remain the customer's responsibility.

Where an approved external model provider is used, the customer provides and controls the provider account, API credentials, quotas, billing and service terms.

A control framework written for your deployment.

Every deployment begins with a joint review of identity, authorization, data flow, encryption, retention, monitoring, backup and recovery requirements. The resulting control framework documents:

Which components run in each environmentWhere customer data, indexes and logs are storedWhich teams administer infrastructure and applicationsWhich model providers are permittedHow access and encryption keys are controlledHow security events are monitored and retainedWhich availability, RTO and RPO commitments apply

The result is an enterprise AI architecture aligned with the organization's existing security boundary — not a separate control model operating outside it.

Your environment. Your policies. Your model access.

AI provider control

Central control over AI providers and application traffic.

Applications integrate with DSX Guard through a governed AI gateway instead of embedding separate provider credentials and policy logic in every service.

Central provider and model configurationCustomer-controlled API credentialsPolicy enforcement before model accessSensitive-data protectionThreat and prompt-injection inspectionModel routing without application redeploymentUsage visibility and audit recordsAPI, webhook, SIEM and DLP integration

Provider choice remains a controlled configuration decision rather than an application rewrite.

Audit evidence

Evidence for security, risk and audit teams.

DSX Digital records the context required to understand what happened without reconstructing it from application logs.

Guard evidence

Who made the request, which managed AI service or application received it, which policy was applied, which data classes were detected and whether the interaction was allowed, masked, blocked or logged.

Insight evidence

Which document was processed, how it was classified, what was extracted, which validations passed or failed, whether human review was required and what was written to downstream systems.

IQ evidence

Who asked the question, which permitted sources informed the response, which passages support each claim and what the system reported about confidence and coverage.

Security and AI activity can be exported or streamed into the enterprise monitoring tools your teams already operate.

Human oversight

Human oversight where policy requires it.

Automation does not remove accountability. DSX workflows can require human review before sensitive decisions, exceptions, approvals or system updates are finalized.

Review requirements can be applied according to:

User or groupDocument classConfidence thresholdData categoryBusiness ruleTarget systemRisk or policy outcome

Human decisions become part of the same audit history as the AI-generated output.

Enterprise controls

Enterprise controls, built into the architecture.

DSX Digital integrates with the identity, security, monitoring and continuity controls enterprises already operate. Control requirements are configured within the customer's private-cloud or on-premises deployment.

Encryption and key management

Data is encrypted in transit and at rest within the customer-controlled deployment environment. Keys, custody, rotation and access policies are defined as part of the private-cloud or on-premises deployment, and can align with your existing key-management and hardware-security controls.

Encryption in transit and at restCustomer-controlled key custodyDefined key rotation and access policiesIntegration with enterprise key-management controlsSeparation of data and key access

Auditability and retention

Retention is configured according to your legal, regulatory and operational requirements. What is recorded for each product is set out under Audit evidence above.

Monitoring and security integrations

Security and operational events can be integrated with the systems enterprise teams already use, and audit records can be exported through supported APIs and webhooks.

SIEM event streamingDLP integrationAPIs and webhooksSecurity and policy alertsDeployment and service monitoringExportable audit records

Availability and resilience

A private-cloud or on-premises deployment can be configured for enterprise availability and continuity requirements.

Deployment-specific high-availability architectureEncrypted backup policiesControlled restoration proceduresService and infrastructure monitoringDefined maintenance processesRecovery testing

API-first integration

DSX Digital connects with enterprise applications without requiring teams to replace the systems they already operate. Provider and gateway configuration is covered above.

REST APIsWebhooksERP, CRM, BPM and document-management integrationInternal application and service integration
Assurance

Security assurance and compliance posture.

DSX Digital maintains a security-assurance program designed to support enterprise vendor review and regulated deployment. The full status, and the documentation available during a review, is published in the Trust Center.

ISO/IEC 27001
Certification program under way — current stage: gap analysis in progress.
Independent penetration testing
Scheduled across all three products; summary published after completion.
Data protection & architecture documentation
Available to qualified organizations under NDA during vendor review.
View Trust Center
FAQ

Frequently asked security questions.

Does customer data leave the controlled environment?

Deployment and model-access policy determine the permitted data path. When an approved external model is used through DSX Guard, protected values are masked inside the customer-controlled environment before the request reaches the provider. A private-cloud or on-premises deployment keeps DSX data processing, indexes, mappings and audit records within the agreed customer boundary.

Does DSX Digital use customer content to train shared models?

No. Customer content is processed only to provide the contracted service and is not used to train shared DSX models.

Can DSX work with local models?

Yes. A private-cloud or on-premises deployment can use customer-hosted local models. DSX does not charge a separate usage fee for those models; infrastructure, compute and model licensing remain the customer's responsibility.

How does DSX IQ enforce document permissions?

IQ reads approved source permissions and enforces them at query time. Answers are constructed only from documents the requesting user is authorized to access.

What does an auditor receive?

Depending on the product, the audit record can include the user, request, model or application, applied policy, detected data classes, decision outcome, document sources, extracted fields, validations, exceptions, approvals and cited answer evidence.

Are all three products required?

No. DSX Guard, DSX Insight and DSX IQ are independently deployable and licensed separately. Organizations can begin with the most urgent requirement and add the other products on the same enterprise security and audit foundation.

Put enterprise AI inside your security boundary.

See how DSX Digital can deploy Guard, Insight or IQ within your private cloud or on-premises environment — and map the architecture to your security, data-residency and integration requirements.

Request a Demo