Fabric

Governed AI Platform

Put AI to work across your organization without sending your confidential data outside it. Fabric runs on your own infrastructure, anonymizes sensitive data before it reaches a cloud model, and governs every model, knowledge base and agent.

About Fabric

Most organizations are caught between two bad options. Cloud models are capable and make work faster, but sending a contract, a customer file or a security report to a service outside the organization is not acceptable, and is sometimes not legal. The usual outcome is one of two things: the tools are banned and the advantage is lost, or people quietly paste the data into personal accounts and nobody knows what left.

Fabric removes the trade-off. It is installed on your own infrastructure and sits between your people and the models: it substitutes sensitive values before a request leaves and restores them when the answer returns, keeps each team and client separated, builds answers from your own documents with citations, runs agents in sandboxes behind human approval, and records every request.

HafezSecure built this platform for its own work, because our security teams face the same limit when handling client data. We use it every day, and we now offer it to organizations that have the same problem.

Anonymized
Sensitive Data on the Way Out
Self-Hosted
On Your Infrastructure
Isolated
Workspace per Team and Client
Audited
Every Request Recorded

Your Data Never Leaves the Organization

For organizations worried about confidentiality when using cloud models: Fabric substitutes sensitive data before the request is sent, and puts it back once the answer arrives

1
Sensitive Values Are Recognized
Before a request leaves your network, Fabric reads it and marks the values you have defined as confidential: personal names, national IDs, phone numbers, account and card numbers, addresses, client names, internal hostnames and IP addresses, file paths, contract figures. The rules are yours to write, and each workspace can add the patterns its own work produces.
2
They Are Replaced, Then the Request Is Sent
Each value is swapped for a neutral placeholder that keeps the shape of the original, so the question still makes sense: one customer stays one customer throughout the text, and a date still reads as a date. Only this anonymized version travels to the external model. The provider receives a coherent question and none of your data.
3
The Answer Comes Back Complete
The answer arrives carrying the placeholders. Inside your own network, Fabric puts the real values back where they belong and hands the finished answer to your colleague. The reader sees a normal, complete answer; the confidential parts of it never crossed your boundary.
What Gets Replaced
  • Names of people, clients and suppliers
  • National IDs, phone numbers, email addresses
  • Account, card and contract numbers
  • Internal hostnames, IP addresses and file paths
  • Figures you mark as confidential
  • Any pattern your own work produces
What Stays Intact
  • The question itself and what it asks for
  • The structure and meaning of the text
  • The relationship between values, kept consistent
  • The quality of the answer you get back

The same rule applies in chat, in knowledge bases, in agent runs and in application calls. For the most sensitive work, restrict a workspace to local models and no request leaves the organization at all.

One Platform, Three Layers

Risky execution is kept away from control and from data, so a mistake in one layer does not reach the next

The Control Layer
Sign-in, workspaces, permissions, model routing, anonymization rules, quotas, budgets and the audit trail. This is where an administrator decides what is allowed, and where every request is recorded.
The Knowledge Layer
Your documents, how they are indexed, and how answers are built from them with citations. Document permissions follow through to retrieval, so a person cannot reach through the assistant to read what they could not open directly.
The Work Layer
Where models run and agents do their work, inside sandboxes with a restricted outbound path. Risky execution is kept here, away from the portal and the data, and nothing reaches the network unless it is on the allow-list.

Key Features

What makes organizational AI trustworthy and accountable

Anonymization Before the Cloud
Use the strongest external models without handing them your confidential data. Sensitive values are masked on the way out and restored on the way back, and the audit trail shows exactly what left the network for every request.
One Gateway for Every Model
Models you run in-house and models you buy sit behind one compatible endpoint. An application written for a common AI interface works unchanged, and switching provider is an administrative setting rather than a development project.
Knowledge Bases That Cite Their Sources
Upload your policies, contracts, reports and manuals, and get answers built from them with a reference to the passage behind each claim. Each person retrieves only from documents they are allowed to open, so the assistant never becomes a way around permissions.
Agents That Ask Permission
An agent can read a report, query a system and prepare a result, but only through tools you registered, inside a sandbox, and it stops for human approval before a step that changes anything. The person who requests a run is not the person who approves it.
Separation Between Teams and Clients
Every workspace is isolated in the database itself, not by a filter in the application, and access is decided per member. A consulting engagement, a subsidiary or a department can share one installation without sharing a single document.
Every Request on the Record
Who asked, which model answered, which documents were used, what it cost and what left the network: all of it is written down. Retention is a policy you set, so logs live as long as your rules require and no longer.
Keys Bound to a Purpose
When another application calls the platform, its key can be tied to one knowledge base and one prompt template with its own quota. A leaked key is then worth very little: it opens one narrow door, and its use shows up in the same audit trail.
Nothing Leaves Without Permission
Outbound traffic follows an allow-list, checked by name and by address, so a model, an agent or a connector can only reach destinations you approved. Everything else is refused and recorded.
Connected to Your Security Work
Connectors bring findings and asset data from the HafezSecure platforms into the same workspace, so an analyst can ask about an exposure and get an answer grounded in the organization’s own current data.
Budgets and Quotas That Hold
Each team, member and key gets a ceiling on how much it may consume, counted on every path including agents and indexing. Spending stays visible while it happens, not at the end of the month.
See How an Answer Was Produced
Each answer can be opened up: which model was used, which passages were retrieved, which tools ran and how long each step took. When a result looks wrong, you can check it instead of arguing about it.
Files in Chat, Without Leaving a Trail
A colleague can attach a document to a conversation and ask about it. The file belongs to that session, follows the same rules as everything else, and does not quietly become part of a shared knowledge base.

Use Cases

Wherever AI work meets data that must not leave

Banks and Regulated Industries
Customer records, transactions and contracts stay inside the bank while staff still use capable models for drafting, review and analysis.
Security Teams Working on Client Data
Findings, logs and reports from one engagement are readable only inside that engagement, and client names never travel to an external provider.
Organization-Wide Assistants
One assistant over your policies, procedures and manuals, answering with citations, so staff stop guessing at internal rules.
Automating Security Workflows
Triage, enrichment and first-draft reporting run as governed agent tasks, with a person approving anything that leaves a mark.
Legal, Audit and Compliance Review
Long contracts and audit evidence are summarized and compared without the documents themselves leaving the organization.
Sectors With Legal Confidentiality Duties
Health, government and other fields where sending personal records to an outside service is simply not permitted.

How It Works

From installation to everyday use

1
Install It on Your Infrastructure
Fabric runs on servers you control, inside your own network. Our team installs it with you, connects it to your sign-in system, and hands over an environment your administrators own from the first day.
2
Connect Your Models
Register the models you want: ones running on your own hardware, ones from a provider you already buy from, or both. Then decide which teams may reach which model, and which work must stay on local models only.
3
Write the Rules Once
Define what counts as sensitive, who may use what, how much each team may spend, how long logs are kept, and which agent steps need a human. These are settings in the portal, not code, and they apply everywhere at once.
4
Your Teams Get to Work
People use chat, knowledge bases and agents through one portal, and other applications call the same gateway. Every request is governed, anonymized where your rules require it, and recorded.

Deployment Options

From a single server to a network with no route outside

A Single Server
Enough for a department or a first rollout: the whole platform on one machine, with your own database and storage.
A Cluster
For heavier use, the same platform spreads across a cluster you operate, keeping teams and workloads separated as they grow.
Fully Offline
With local models only, Fabric works with no route to the internet at all, which suits classified networks and air-gapped sites.

Why Fabric

How it differs from using AI services directly

Confidentiality Is the Default
The question "can we use this model without leaking our data?" is answered by the platform, not by asking every colleague to be careful. The rule is enforced on the way out, for everyone, on every path.
You Own the Whole Platform
It is installed on your hardware and keeps working without any outside service. For organizations that cannot depend on foreign providers, that is the difference between adopting AI and postponing it.
Governance Instead of Guesswork
Access, budgets, retention and approvals are administered centrally, so use can spread across the organization without anyone losing sight of the cost or the risk.
Built by a Security Company, In Daily Use
Fabric is the platform HafezSecure built for its own work and runs every day. Isolation, auditing and least privilege are part of its design rather than features added after an incident.

Frequently Asked Questions

What organizations ask before deciding on Fabric

Does our data ever reach the model provider?
What exactly gets anonymized?
What if something sensitive is not recognized?
Can Fabric work with no internet connection at all?
Which models can we connect?
How is one team kept separate from another?
Can staff use the assistant to read documents they should not see?
How do we keep costs under control?
What can an agent do without a human?
What do we need in order to run it?
How does Fabric relate to your other platforms?
Do we have to change our applications to use it?
AI Without the Data Worry
Contact our team to see Fabric and discuss installing it on your own infrastructure