Enterprise AI, deployed inside your control boundary.
DSX Digital is built for organizations that handle sensitive documents, regulated data and business-critical AI workflows. DSX Guard, DSX Insight and DSX IQ can be deployed in your private cloud or on-premises, with enterprise policy, access control, auditability and human oversight designed into the architecture.
Every managed path to AI is governed before data reaches a model. Every document-derived decision can be traced to its source. Every answer across enterprise knowledge respects the permissions of the person asking.
One security standard across all three products.
Security is not a separate feature added after deployment. It is the shared foundation underneath DSX Guard, DSX Insight and DSX IQ.
DSX Guard
Governs every managed path to AI — employees, applications and agents — under one policy set, and records what happened.
DSX Insight
Keeps source references, confidence scores, review decisions and process history attached to every document-derived output.
DSX IQ
Indexes the estate in place, retrieves only what the person asking may see, and cites the document, page and passage behind every answer.
One policy foundation. One audit standard. Three independently deployable products.
Protect sensitive data before it reaches an external model.
DSX Guard evaluates managed AI requests before they leave your controlled environment. Values defined as sensitive by your organization can be masked, blocked, allowed or logged according to policy.
Detect
Identify personal, financial, health, commercial and technical information using built-in and organization-specific definitions.
Protect
Replace protected values with structured placeholders before an external model receives the request. Files and attachments are inspected under the same policy.
Restore
The mapping remains inside your controlled environment. When an approved answer returns, authorized values are restored before the response reaches the user.
External providers receive only the content permitted by your policy — not the original protected values.
Explore DSX GuardIdentity, permissions and separation.
Access to DSX products is governed by enterprise roles, product permissions and source-system entitlements, integrated with the identity provider your organization already runs.
Enterprise identity
Integrate DSX Digital with your enterprise identity provider through SAML 2.0 or OpenID Connect. Existing authentication policies — including multi-factor authentication — remain centrally enforced.
User lifecycle management
Automate user and group provisioning through SCIM so access reflects changes in the enterprise directory.
Role-based access control
Separate administrative, operational, review and standard-user responsibilities across DSX Guard, DSX Insight and DSX IQ.
DSX IQ does not grant access to a document simply because a user asks about it. An answer is assembled only from sources that the requesting user is authorized to access.
No source migration. Your documents stay where they are.
DSX IQ connects to approved file servers and enterprise repositories using controlled, read-only access. Source documents remain in the systems your organization already manages.
Within your controlled environment, IQ creates a derived, permission-aware index for retrieval and whole-corpus reasoning beyond a single context window. Folder structure, document metadata, source location and access permissions remain part of the evidence behind each answer.
Document decisions that survive review.
DSX Insight preserves the evidence behind document processing from intake to system update.
Low-confidence output is routed for review rather than silently accepted. What was extracted, what passed validation, what failed and who approved the result remain available as part of the process record.
Explore DSX InsightDeployment inside your security boundary.
DSX Guard, DSX Insight and DSX IQ are deployed within an environment controlled by the customer. Choose private cloud or on-premises according to your data-residency, infrastructure, model-access and operating requirements.
| Private cloud | On-premises | |
|---|---|---|
| Deployment location | Deployed within the customer's private-cloud environment | Deployed within the customer's data center or controlled on-premises infrastructure |
| Data boundary | Customer data, indexes, mappings and audit records remain inside the customer-controlled cloud boundary | Customer data, indexes, mappings and audit records remain inside the customer-controlled on-premises boundary |
| Model access | Customer-hosted models or customer-approved external model providers | Local models or customer-approved external model providers |
| Infrastructure and compute | Provided and controlled by the customer within its private-cloud environment | Provided and controlled by the customer within its own infrastructure |
Everything else follows your controls rather than the shape of the deployment: sensitive-data protection, identity and access, encryption and key management, logging and retention, monitoring integration, availability and recovery, change management and the division of operating responsibility are set the same way in both models and are covered below.
Customer-controlled model usage
Where customer-hosted local models are used, DSX Digital does not charge a separate model-usage fee. Infrastructure, compute capacity and model licensing remain the customer's responsibility.
Where an approved external model provider is used, the customer provides and controls the provider account, API credentials, quotas, billing and service terms.
A control framework written for your deployment.
Every deployment begins with a joint review of identity, authorization, data flow, encryption, retention, monitoring, backup and recovery requirements. The resulting control framework documents:
The result is an enterprise AI architecture aligned with the organization's existing security boundary — not a separate control model operating outside it.
Your environment. Your policies. Your model access.
Central control over AI providers and application traffic.
Applications integrate with DSX Guard through a governed AI gateway instead of embedding separate provider credentials and policy logic in every service.
Provider choice remains a controlled configuration decision rather than an application rewrite.
Evidence for security, risk and audit teams.
DSX Digital records the context required to understand what happened without reconstructing it from application logs.
Guard evidence
Who made the request, which managed AI service or application received it, which policy was applied, which data classes were detected and whether the interaction was allowed, masked, blocked or logged.
Insight evidence
Which document was processed, how it was classified, what was extracted, which validations passed or failed, whether human review was required and what was written to downstream systems.
IQ evidence
Who asked the question, which permitted sources informed the response, which passages support each claim and what the system reported about confidence and coverage.
Security and AI activity can be exported or streamed into the enterprise monitoring tools your teams already operate.
Human oversight where policy requires it.
Automation does not remove accountability. DSX workflows can require human review before sensitive decisions, exceptions, approvals or system updates are finalized.
Review requirements can be applied according to:
Human decisions become part of the same audit history as the AI-generated output.
Enterprise controls, built into the architecture.
DSX Digital integrates with the identity, security, monitoring and continuity controls enterprises already operate. Control requirements are configured within the customer's private-cloud or on-premises deployment.
Encryption and key management
Data is encrypted in transit and at rest within the customer-controlled deployment environment. Keys, custody, rotation and access policies are defined as part of the private-cloud or on-premises deployment, and can align with your existing key-management and hardware-security controls.
Auditability and retention
Retention is configured according to your legal, regulatory and operational requirements. What is recorded for each product is set out under Audit evidence above.
Monitoring and security integrations
Security and operational events can be integrated with the systems enterprise teams already use, and audit records can be exported through supported APIs and webhooks.
Availability and resilience
A private-cloud or on-premises deployment can be configured for enterprise availability and continuity requirements.
API-first integration
DSX Digital connects with enterprise applications without requiring teams to replace the systems they already operate. Provider and gateway configuration is covered above.
Security assurance and compliance posture.
DSX Digital maintains a security-assurance program designed to support enterprise vendor review and regulated deployment. The full status, and the documentation available during a review, is published in the Trust Center.
Frequently asked security questions.
Does customer data leave the controlled environment?
Deployment and model-access policy determine the permitted data path. When an approved external model is used through DSX Guard, protected values are masked inside the customer-controlled environment before the request reaches the provider. A private-cloud or on-premises deployment keeps DSX data processing, indexes, mappings and audit records within the agreed customer boundary.
Does DSX Digital use customer content to train shared models?
No. Customer content is processed only to provide the contracted service and is not used to train shared DSX models.
Can DSX work with local models?
Yes. A private-cloud or on-premises deployment can use customer-hosted local models. DSX does not charge a separate usage fee for those models; infrastructure, compute and model licensing remain the customer's responsibility.
How does DSX IQ enforce document permissions?
IQ reads approved source permissions and enforces them at query time. Answers are constructed only from documents the requesting user is authorized to access.
What does an auditor receive?
Depending on the product, the audit record can include the user, request, model or application, applied policy, detected data classes, decision outcome, document sources, extracted fields, validations, exceptions, approvals and cited answer evidence.
Are all three products required?
No. DSX Guard, DSX Insight and DSX IQ are independently deployable and licensed separately. Organizations can begin with the most urgent requirement and add the other products on the same enterprise security and audit foundation.
Put enterprise AI inside your security boundary.
See how DSX Digital can deploy Guard, Insight or IQ within your private cloud or on-premises environment — and map the architecture to your security, data-residency and integration requirements.
Request a Demo