Expressible
Security & compliance

Built for environments where every decision must be defended.

Expressible deploys inside your boundary and is architected for the strictest environments. Your data never leaves your perimeter, every decision is recorded, and the control architecture is designed to meet federal and regulated frameworks — with formal authorization pursued inside your authorization boundary.

Deployment & data sovereignty

The platform runs where your data lives. There is no requirement to send content to a vendor cloud.

Air-gapped & on-premises

Deploy in your own data center, your managed cloud, or a fully isolated network with no internet connectivity.

Zero outbound telemetry

No external API calls are required at runtime. Nothing phones home.

No training on your data

Your content is used to answer your questions, never to train a shared model.

Single-tenant isolation

A dedicated, isolated deployment per customer — no data shared across tenants.

Data residency

Your data stays in the region and environment you choose.

U.S. & allied model provenance

Defense deployments run on U.S. and allied open-weight models, served inside your boundary.

Data protection

  • AES-256 encryption for data at rest
  • TLS 1.3 for data in transit, enforced end to end
  • Logical and physical separation between deployments
  • FIPS-validated cryptography available for federal deployments

Access & identity

  • Role-based access control with least-privilege defaults
  • SSO via SAML 2.0 / OIDC, integrating with your identity provider
  • Multi-factor authentication and managed sessions
  • US-person-only access handling for ITAR-controlled engagements

Auditability is the point, not an afterthought

Every governed interaction and material platform action is captured in an append-only record, available for internal review, compliance audits, regulatory examination, and legal discovery.

Append-only audit trail

Queries, retrieved sources, recommendations, confidence, human overrides, and executed actions — timestamped and attributed.

Decision records

Each deliberation is preserved with hypotheses, dissent, and citations — exportable as a defensible report.

SIEM export

Audit events can be exported to your security monitoring stack.

Security in the delivery pipeline

Where the platform generates or transforms code, security review is embedded into delivery rather than performed after the fact. Findings are classified by severity, mapped to common-weakness identifiers, and preserved as part of the record.

Coverage spans the OWASP Top 10 and additional common weakness categories, with file-level references and remediation guidance.

  • Static analysis against OWASP Top 10 and CWE categories
  • Findings classified by severity with remediation guidance
  • Generated code free of unsafe dynamic execution (CSP-safe)
  • Results preserved in the audit record, not discarded

Compliance posture

The platform's control architecture is designed to meet the frameworks below. Where a framework requires a formal authorization, we pursue it inside your authorization boundary as part of the engagement — for example, an agency ATO is achieved within the customer's environment.

Designed to support

FedRAMP

Control families aligned; path to ATO within your authorization boundary.

Self-assessed

CMMC Level 2

Practices implemented for controlled unclassified information handling.

Architected for

DoD IL4 / IL5

Deployable into impact-level environments within the customer's accredited cloud.

Control-aligned

PCI DSS

Encryption, access control, and audit controls aligned to PCI requirements.

Control-aligned

HIPAA

Safeguards aligned to the HIPAA Security Rule for protected health information.

Controlled handling

ITAR

US-person-only access and in-boundary processing for controlled technical data.

Expressible is an early-stage company and does not represent these as completed third-party certifications. We are happy to share our current control documentation and authorization roadmap under NDA.

Talk to our team about your security requirements

We'll walk through deployment options, control mappings, and the authorization path for your environment.