Configure →
Trust package

The paperwork and operating controls that make private AI buyable.

For professional buyers, local inference is only the beginning. The system also needs clear documents, deletion evidence, update boundaries, model provenance, and a security contact that can be used before procurement.

GDPR / DPA pack

Available now

Controller and processor roles, sub-processor list, transfer safeguards, and a data processing agreement for business customers that need one.

TOMs

Available now

Technical and organisational measures covering access control, encryption posture, logging, backups, provisioning handling, and incident response.

Retention policy

Available now

Defined operating periods for logs, order records, support material, and optional Pre-Load files, with shorter retention for customer content.

Deletion certificate

Available now

For Pre-Load provisioning, selbsai can provide a written deletion confirmation after customer files are wiped from provisioning storage.

Model provenance

Operational template

Each delivered system identifies model families, source locations, license class, intended workload, runtime, format, update channel, and verification references where available.

Update policy

Operational template

Security updates, model refreshes, and compatibility updates are separated into stable, balanced, and fast-track channels so customers can choose stability or newer capability deliberately.

security.txt

Operational template

A machine-readable disclosure contact is published at /.well-known/security.txt and points to the current security policy.

Vulnerability policy

Operational template

Security reports can be sent to the published security contact and are triaged for customer impact, severity, remediation, and disclosure handling.

Delivered Model Provenance Card

For configured systems, the customer-facing trust package can include a concise record of what model stack was selected and why it is appropriate for the device.

Source repository, model card, publisher, release date, and license posture.
Runtime and format: Ollama, llama.cpp, MLX, vLLM, GGUF, Safetensors, or another selected path.
Intended workload, known limitations, language fit, and benchmark references used during selection.
Checksum or verification reference where available, plus the selected stable, balanced, or fast-track update channel.
Status

This page describes the trust package selbsai maintains for customers. Customer-specific DPA and TOM documents are provided during business onboarding where required.

Security contact: security@selbsai.com

Trust package — SELBSAI