The paperwork and operating controls that make private AI buyable.
For professional buyers, local inference is only the beginning. The system also needs clear documents, deletion evidence, update boundaries, model provenance, and a security contact that can be used before procurement.
GDPR / DPA pack
Available nowController and processor roles, sub-processor list, transfer safeguards, and a data processing agreement for business customers that need one.
TOMs
Available nowTechnical and organisational measures covering access control, encryption posture, logging, backups, provisioning handling, and incident response.
Retention policy
Available nowDefined operating periods for logs, order records, support material, and optional Pre-Load files, with shorter retention for customer content.
Deletion certificate
Available nowFor Pre-Load provisioning, selbsai can provide a written deletion confirmation after customer files are wiped from provisioning storage.
Model provenance
Operational templateEach delivered system should identify the model families, source locations, license class, intended workload, and update channel.
Update policy
Operational templateSecurity updates, model refreshes, and compatibility updates are separated so customers can choose stability or newer capability deliberately.
security.txt
Operational templateA machine-readable disclosure contact is published at /.well-known/security.txt and points to the current security policy.
Vulnerability policy
Operational templateSecurity reports can be sent to the published security contact and are triaged for customer impact, severity, remediation, and disclosure handling.
This page describes the trust package selbsai maintains for customers. Customer-specific DPA and TOM documents are provided during business onboarding where required.
Security contact: security@selbsai.com