Security
How SetMeld is architected for organizations whose data cannot leave their network.
Architecture first
The strongest security property SetMeld offers comes from architecture: in the self-hosted deployment model, we do not operate anything. SetMeld Composer, SetMeld Pipeline, the knowledge graph and the reasoning model all run inside your own network. No data, and no schema description of that data, is transmitted to SetMeld.
In the SetMeld Cloud model, both components run in our environment and connect to your sources over secure channels, but the authoritative unified graph is loaded back into your network and queries are served from there.
Controls in the product
- Access control. Permissions travel with the graph; agents and applications inherit the controls that govern the underlying data.
- Provenance. Datasource attribution is carried on every record and returned with every answer.
- Audit trails. Every transformation and every SetMeld Pipeline run is logged, with timings.
- Reviewable design. Nothing executes until your team approves the generated extraction plans, transformation logic and entity resolution rules.
- Customer-chosen models. Self-hosted deployments reason with an LLM you select and host.
Certifications
We do not currently publish a certification badge on this page, and we would rather tell you that plainly than imply otherwise. If your procurement process requires specific attestations, raise it on the first call and we will tell you exactly where we stand and what we can support.
Reporting a vulnerability
If you believe you have found a security issue in SetMeld or in this website, please write to info@setmeld.com with enough detail to reproduce it. We will acknowledge and keep you updated, and we will not pursue action against good-faith research.
Bring your security team to the first call.
The architecture conversation is usually shorter than expected.