Informer AI Data Security & Governance
How the Informer platform protects your data when you use AI, including in Informer GO. Provider choice, the query-not-data architecture, and governance the AI cannot be talked around.
What's Inside
Five things every security review asks.
Get the White Paper
The PDF opens right away, and we'll email a copy for your records.
Your download is ready.
The white paper should open automatically. If it didn't, use the button below.
Download the PDFRunning Informer before 2026.1? Get the earlier edition.
Trust Posture at a Glance
The short answers. The paper shows the mechanism.
Is my raw data sent to the AI?
Not in bulk. The model receives your question and a description of your data's structure. It proposes a query, Informer runs that query inside your instance, and only the results come back, favoring aggregates.
Can the AI see data I can't?
No. Every query runs under your own identity and permissions. Data that was never shared with you is absent from the AI's view entirely, so it has no knowledge that it exists.
Can a crafted prompt or jailbreak get around that?
No. Access is enforced beneath the model at the data layer rather than by instructing the model, so there is no instruction to override and nothing for the model to discover.
Is my data used to train models?
No. Under the managed service, Entrinsik's enterprise agreements prohibit training on your prompts or results. With BYOK it follows your own provider agreement. With a local model your data never leaves your network.
Where does my data live?
In your Informer instance, whether on-premises or in a dedicated cloud environment. Only usage metrics are shared with Entrinsik, for billing, never your data or conversations.
Independently attested
Entrinsik maintains a SOC 2 Type 2 attestation covering the Security Trust Services Criteria. The full report is available to customers and prospects under NDA.
Questions the paper doesn't answer?
Security reviews rarely stop at a document. Talk to the team that builds the platform about your own deployment, provider posture, and compliance requirements.