Security
A control plane must be held to a higher standard than what it governs.
Griffin is designed to minimise the data it retains, to keep enforcement close to your estate and to make every decision reconstructable.
Architecture
Deployment and isolation.
Deployment options
Content for managed, private-region and self-hosted enforcement.
Tenancy isolation
Content for isolation boundaries and key separation.
Data residency
Content for regional processing and residency commitments.
Data handling
What Griffin stores, and what it does not.
Retention
Content for configurable retention and metadata-only modes.
Encryption
Content for encryption in transit and at rest, and key management.
Access control
Content for administrative access, approvals and separation of duties.
Assurance
Assurance and disclosure.
Assurance roadmap
Content for the independent assurance roadmap. No certification is claimed at this stage.
Penetration testing
Content for third-party testing cadence and summary reporting.
Responsible disclosure
Content for the vulnerability disclosure process and contact route.
Discuss your AI governance programme
Griffin is working with a small number of design partners in regulated sectors. If you are accountable for how AI is used across your organisation, we should speak.