Architecture

Layered AI security architecture for real enterprise control.

Impenetrix is organized as security planes: discovery, enforcement, privacy, reasoning, ingestion, tool governance, operations, and evidence.

Architecture overview

Users, applications, agents, and IDEs send AI-bound activity through AI Traffic Control. Policy enforcement and redaction govern the path to model providers, internal model gateways, retrieval systems, and tools. Every decision creates evidence.

AI activity enters a control point.Payloads are classified and risk scored.Policy decides allow, block, redact, route, or escalate.Approved requests reach models, retrieval systems, or tools.Responses and tool results are inspected.Evidence is preserved for audit and investigation.

Core planes

Each plane has a job. Together they create a chain of custody from AI activity to policy decision to evidence.

Enforcement plane

AI egress proxying, provider controls, prompt/response scanning, redaction, findings, alerts, policy simulation, evidence capture, and admin workflows.

Reasoning plane

Defensive AI security analysis, cited answers, risk explanation, control mapping, incident triage, prompt-injection review, and remediation support.

Control plane

Workers, queues, Postgres, Redis, NATS, MCP lifecycle, faasd/serverless execution, audit, rate limits, metrics, and source ingestion.

Privacy plane

Detection and redaction for PII, secrets, credentials, sensitive prompts, retrieved context, logs, outputs, and training/evaluation data.

Operations plane

Service health, queue lag, disk usage, worker state, certificate expiry, deployment status, backup status, and control operation.

Technical depth: data flow

The important part is not a dashboard. It is a defensible chain from AI activity to policy decision.

  1. Capture AI request metadata and payload context.
  2. Classify provider, user, app, model, data type, destination, and tool intent.
  3. Run redaction and data-protection rules.
  4. Evaluate policy and exceptions.
  5. Allow, block, redact, route, or require approval.
  6. Inspect responses and tool outputs.
  7. Write evidence, policy version, findings, and response history.

Need a technical architecture review?

Send us your AI path, model providers, tool plans, and current controls. We will map likely enforcement points.