Built to pass your security review.
Gerniq is self-hosted software. It runs in your cluster, stores data in your systems and authenticates through your identity provider.
What stays in your environment: everything.
Documents, prompts, model weights, results, logs and metrics are stored in your cluster and your systems.
| Gerniq receives by default | Nothing |
| Optional, off by default | Anonymous usage telemetry |
| Only if you choose to send it | Support bundles (configuration and logs) for troubleshooting |
Security built into the platform, not bolted on.
Identity and access
Single sign-on through your OIDC identity provider, role-based access, service accounts and per-tenant API credentials.
Network
TLS on every endpoint through cert-manager, Kubernetes network policies, and optional mutual TLS through a service mesh.
Supply chain
Signed container images, a software bill of materials (SBOM) for every release, and version-pinned runtimes.
Audit and retention
Audit log of deployments, configuration changes and API access, with retention you configure and export to your SIEM.
Secrets
Secrets come from your vault through External Secrets Operator. Nothing sensitive is baked into images or config files.
Isolation
Per-tenant quotas, namespace isolation for custom models and Kubernetes Pod Security Standards.
Evidence, published as it is earned.
We only list certifications once they are complete. Here is where each one stands today.
Last updated 29 September 2026.
- Security overview and data-flow documentFor design partners
- Third-party VAPT by a CERT-In empanelled auditorPlanned
- DPDP-ready data processing addendumPlanned
- ISO/IEC 27001 certificationPlanned
- SOC 2 Type I, then Type IIPlanned
Keep personal data under the controls you already have.
Banks, insurers and hospitals in India are data fiduciaries under the Digital Personal Data Protection Act, 2023, and the DPDP Rules, 2025 phase in obligations through 13 May 2027. Banks and NBFCs are also working through the Reserve Bank of India's FREE-AI framework for responsible AI.
Running inference inside your own environment keeps personal data under your existing access controls, retention rules and breach processes, instead of adding a new external processor. Gerniq does not make you compliant on its own, but it removes one of the hardest questions from your AI projects: where does the data go?
Bring your security questionnaire.
We will walk your security team through the architecture, data flows and controls, and answer your questionnaire in writing.