Tenant-isolated deployments, end-to-end encryption, and a typed-object data layer that makes cross-firm leakage architecturally impossible.
Every firm runs in its own isolated Palantir Foundry deployment, a sealed black box. Your data, your ontology, your agents. Zero cross-customer access.
Antonine does not train models — not on your data, not on anyone's. Your data is used to answer your firm's questions and nothing else. Model calls run through Palantir's managed service, so their terms with the underlying providers govern retention — published in full at Palantir's trust center.
AES-256 at rest, TLS 1.3 in transit. Customer-managed keys available on enterprise deployments.
Every agent action, query, and output is logged with full lineage. Every figure in a memo links back to its source document.
Agents cannot reach data outside the typed-object graph they have been granted. A Comp Match cannot leak across funds. The type system enforces it.
Deploy on a private Foundry instance your team controls. For NDA-protected deal data, local models keep nothing leaving your network.
Antonine is not SOC 2 certified today. Controls are being implemented now, with the Type II examination aimed at Q4 2026.
Palantir holds SOC 2 Type II and ISO 27001 for Foundry, the platform we deploy on. These are Palantir's certifications, not Antonine's.
Encryption at rest and in transit on every deployment. CMK available on enterprise tier.
Optional dedicated instance on your VPC, with local models for NDA-protected data.
Data-processing and subject-rights controls in build.
Every decision linked to its source, every output auditable, every agent bound by the ontology's type system — so nothing reaches your team that you can't defend.