Everything on this page describes how Eclypse actually runs, in every deployment we operate — including fully air-gapped, with no outbound connectivity and no public-model training. It is not a tier you upgrade into — it is the architecture.
The engine, the Validator Framework, and the registry install as one system inside whichever boundary your data already lives behind.
In-country tenancy under your account and controls, including Singapore's Government Commercial Cloud.
Runs on your hardware behind your firewall, integrated with your identity provider and logging stack.
No outbound connectivity. Local model serving, with module updates applied on your schedule.
For multi-site research, source data stays with the originating site; only de-identified, permitted derivatives move.
Every module declares the data it may touch. Agents and users can only call what their role permits — permissioning is a property of the registry, not a policy layered on top.
Every agent run is logged: which modules fired, what evidence was retrieved, which checks passed, and who signed off. The log is not editable after the fact.
A module change ships as a controlled release with a diff, never a silent prompt edit. Outputs stay reproducible against a known version.
This is the one commitment every deployment topology shares, regardless of how "closed" the environment already is. Nothing your team or Eclypse runs through the platform is used to train a public or foundation model — not for fine-tuning, not for evaluation, not by default and not by exception.
Approval gates are part of the workflow definition, not a setting someone can switch off under deadline pressure. Nothing is auto-selected or auto-published — a named specialist reviews reasoning and sources before a deliverable is used.
A second model class, plus rule-based checks, tests claims, statistics, and references before a draft ever reaches the expert workspace. Verification is a pipeline stage, not a hope.
The Validator Framework tracks where each fact came from and when it changed. Every output resolves to its source document, version, and the agent run that produced it — traceability is a property of the data model, not a report generated afterward.
Agents are constrained to their registered tools and declared data scope. An agent cannot reach past what its role permits, and every capability it calls is versioned and reviewable.
Designed from the ground up for the most demanding regulatory and data-residency requirements.
No. Client operations and proprietary data are never used to train a public or foundation model, in any deployment topology — sovereign cloud, on-premise, air-gapped, or site-resident.
Wherever you choose: in-country sovereign tenancy (including Singapore's Government Commercial Cloud), on your own hardware behind your firewall, fully air-gapped with no outbound connectivity, or resident at the originating site for multi-site research. The default is that data does not leave your environment.
Yes, by design. Every deliverable is reviewed and signed off by your specialist before it is used; nothing is auto-selected or auto-published. Agent outputs pass a second model class plus rule-based checks before a human ever sees them.
Yes. Every output resolves to its source document, version, and the agent run that produced it, through the Validator Framework's provenance tracking and an immutable audit log.
ISO 27001 and SOC 2 alignment, GDPR and PDPA compliance, and HIPAA / BAA readiness, with role-based access control by default.
Our proprietary AI orchestration platform for healthcare: one engine, a registry of reusable task modules and domain agents, and a governed knowledge base — deployed inside your walls and run by your team.