Skip to main content
White Paper

Informer AI Data Security & Governance

How the Informer platform protects your data when you use AI, including in Informer GO. Provider choice, the query-not-data architecture, and governance the AI cannot be talked around.

26 pages Written for security reviewers and procurement Informer 2026.1 and later

What's Inside

Five things every security review asks.

You choose where the AI runs
Use Informer's managed AI service, bring your own provider key, or run a model entirely inside your own network. OpenAI, Anthropic, Google, Amazon Bedrock, and self-hosted models are all supported.
The AI answers your questions without ever receiving your data
It gets your question and a description of how your data is organized, never the data itself. It proposes a query, Informer runs that query inside your instance, and only the results come back.
The AI inherits your permissions and can't be talked around them
Every query runs under your own identity. Because the limit is enforced beneath the model at the data layer, prompt injection and jailbreaks have no instruction to override.
Your data is not used to train models
Entrinsik uses enterprise API tiers whose agreements prohibit training on your prompts or results. With your own key, your provider agreement governs. With a local model, the question never leaves.
Your data stays in your instance
Analytical data and AI conversations remain in your instance, on-premises or in a dedicated cloud. Only usage metrics are shared with Entrinsik, for billing.

Get the White Paper

The PDF opens right away, and we'll email a copy for your records.

Trust Posture at a Glance

The short answers. The paper shows the mechanism.

Is my raw data sent to the AI?

Not in bulk. The model receives your question and a description of your data's structure. It proposes a query, Informer runs that query inside your instance, and only the results come back, favoring aggregates.

Can the AI see data I can't?

No. Every query runs under your own identity and permissions. Data that was never shared with you is absent from the AI's view entirely, so it has no knowledge that it exists.

Can a crafted prompt or jailbreak get around that?

No. Access is enforced beneath the model at the data layer rather than by instructing the model, so there is no instruction to override and nothing for the model to discover.

Is my data used to train models?

No. Under the managed service, Entrinsik's enterprise agreements prohibit training on your prompts or results. With BYOK it follows your own provider agreement. With a local model your data never leaves your network.

Where does my data live?

In your Informer instance, whether on-premises or in a dedicated cloud environment. Only usage metrics are shared with Entrinsik, for billing, never your data or conversations.

Independently attested

Entrinsik maintains a SOC 2 Type 2 attestation covering the Security Trust Services Criteria. The full report is available to customers and prospects under NDA.

Questions the paper doesn't answer?

Security reviews rarely stop at a document. Talk to the team that builds the platform about your own deployment, provider posture, and compliance requirements.