Research · August 15, 2026

Enterprise data boundaries: exclusion by architecture, not by promise

What it takes to make training exclusion a structural property of a deployment.

Summary

A technical note on enterprise data boundaries: tenant isolation, egress control through a single gateway, provider-level training exclusion, and the record that proves which data left the boundary, when, and under whose directive.

Full text

The record

The enterprise concern is not where data physically sits. It is whether the enterprise's data can end up improving somebody else's model.

Isolation

Tenant content is separated by construction. No shared corpus, no cross-tenant retrieval, no path by which one customer's records shape another customer's execution.

A single point of egress

The Data Control Gateway is the only route out of the boundary. Because egress is funnelled through one control, what leaves can be filtered, minimised, redacted, or refused according to policy, and it can be counted.

Provider training exclusion

Calls to external providers are made under terms and configurations that exclude enterprise content from training. Where a provider cannot offer that, the route is not an approved route — a routing constraint, not a caveat in a contract nobody reads.

Proof

Every egress is recorded against the directive that caused it: what left, when, under whose role, to which provider, and under which policy version. The enterprise can answer the training question with a record instead of an assurance.

Corrections welcome, in writing.

If a figure we published is wrong, we want the citation. Research correspondence goes straight to the founding team.