Built for rooms where the draft can't leave

Diplomatic institutions handle the drafts, positions, and counterpart intelligence that foreign policy is built on. The moment any of that material touches a public AI, it is no longer yours to control. Attaché is built for the opposite: a workspace where your data is yours, your drafts don't train models, and classification gates are enforced at the infrastructure layer - not the honour system.

Commitments

No training on your data. Attaché does not use your drafts, dossier contents, prompts, or outputs to train or fine-tune any AI model. This commitment extends contractually to every model provider — Anthropic, Mistral AI, Google, and Perplexity — whose APIs power the platform. Each API call is governed by explicit no-training terms. Your Talking Points, your Travel Files, your counterpart notes stay yours.


EU data residency. All Subscriber Content — every draft, dossier upload, agreed-language entry, counterpart profile, and cleared document — is hosted in data centres located within the European Union. We do not replicate your content to servers outside the EU without written agreement. Hosting region and retrieval scope are deliberately separate controls; changing your region focus in the workspace never moves your data.


Tenant isolation. Every mission and ministry account is isolated from every other at the database level through row-level security enforced at the query layer — not the application layer. A misconfigured permission cannot expose one tenant's dossier to another. Your files are structurally unreachable from any other account.


Controls at a glance

Classification routing. When a session or document is marked Restricted or Confidential, live external retrieval is disabled automatically at the API and database layers. The officer cannot accidentally run an open-web search against a confidential draft. Retrieval stays inside official corpora and your workspace — the classification gate cannot be toggled off from the UI.


Append-only audit log. Every material action in the platform — drafts created, documents accessed, exports generated, clearance queue changes, source retrievals, classification changes — is recorded in an audit log that cannot be modified or deleted. You can export it. We cannot alter it.


Access Principle of least privilege for all personnel, multi-factor authentication required, unique user IDs, encrypted endpoints, endpoint detection and response tools on all staff devices.


EU data residency

Device security for officers Screen Shield (Shift+S) hides the workspace instantly. Vault Lock adds a per-dossier PIN layer independent of session authentication. Local Wipe clears cached data without affecting server-side content. Biometric unlock and auto-lock on idle. These are device-local controls for open offices, hotels, and embassies — they do not replace classification labels or organisational MFA.


AI provider chain Contractual no-training terms with every model provider. Prompt content is never used for model improvement. Providers process requests to return a response and are contractually prohibited from retaining Subscriber Content for any other purpose.


Data and residency EU hosting, no cross-border replication without agreement, tenant isolation via row-level security, classification-gated retrieval. Encryption AES-256 at rest, TLS 1.2 or higher in transit, hardware security module key management, regular key rotation, keys separated from data.


How Attaché handles confidential documents

You choose where the model runs. Attaché is model-agnostic by design: a routing layer decides where inference happens, and classification policy binds every option equally.

European cloud (default). Primary drafting on European-hosted frontier models under contractual no-training terms, with subscriber content stored in the EU under tenant isolation. Full capability, no configuration.

Swiss sovereign cloud. Opt-in routing to open-weight models served from Swiss data centres. Queries are not stored and never used for training - and because the models are open, that guarantee is verifiable in public weights, not just contractual.

Your own infrastructure. Point Attaché at an inference endpoint you control - on your mission's network or in your national cloud region. A workspace can also enforce a hard rule: classified drafting is refused entirely unless it runs on your endpoint.

Whichever you choose, nothing else changes: citations, playbooks, agreed language, the Protocol Score, and classification gates operate above the model layer and apply identically.

See what left the tenant. After any draft, Attaché shows exactly what crossed the boundary: which passages went to which provider, in which region - and what was never stored. Not a policy promise; a per-draft disclosure read from the audit log. During drafting, a scope chip names the active classification and sources, and nothing enters a draft's context without being declared.


Every draft in Attaché carries a classification, and the platform - not user discipline - enforces what that classification permits.

Unclassified. Full capability: dossier retrieval, the curated UN/OSCE/EU corpus, and tier-labelled live research across 250+ vetted domains.

Restricted and Confidential. Live web research is disabled at the API layer - the request never leaves the platform, whichever model or setting is active. Retrieval is confined to your own dossier, pinned agreed language, and the pre-ingested corpus. The gate extends below the surface: for classified drafts, even embedding and search queries are not sent to external research providers. No query text leaves your tenant.

Confidential Mode. One action locks the workspace posture: a persistent banner, automatic vault locking, external retrieval blocked, watermarked exports - and, for organisations that require it, ephemeral inference, where nothing about the session is retained.

Connected files are referenced, never copied. When you connect a drive or document store, confidential-tier retrieval is federated: Attaché fetches passages at the moment of drafting and stores no copy. Disconnect, and the references are purged.

Everything is on the record - yours. An append-only audit log records every retrieval, generation, and export. Drafts remain drafts until an officer reviews them: Attaché prepares the package for clearance; transmission remains yours.

frontier models on sovereign cloud

Open-weight models on the Swiss sovereign cloud

The Swiss sovereign option runs open-weight, openly licensed models on Swiss infrastructure - chosen for provenance, licence clarity, and drafting quality:

  • Apertus 70B - the fully open Swiss model built by EPFL and ETH Zürich (Apache 2.0). Weights, training-data recipes, and EU AI Act transparency documentation are public; trained on 1,800+ languages with respect for data opt-outs. The most transparent model available anywhere - built for exactly this kind of institution.

  • Mistral open-weight models - European open models (Apache 2.0) for high-quality general drafting and fast, economical tasks.

  • Gemma - Google's open-weight family (open licence), strong multilingual analysis and long-document work.

  • GPT-OSS - OpenAI's open-weight release (Apache 2.0), a powerful open option for reasoning-heavy tasks.

  • Open embedding models - multilingual open-source embedding models power semantic retrieval on the same Swiss infrastructure, so search queries can stay sovereign too.

Every model in the sovereign catalogue is openly licensed and served from Swiss data centres under Swiss and EU data-protection law. We document the provenance of every model we route to - and models with provenance considerations are never used by default.

Frequently asked questions

Not sure where to start? Reach out with any questions, or if you're ready to dive right in, schedule a free consultation today.

Attaché is built to meet the confidentiality requirements of diplomatic institutions.

Security and controls

No training on your data

EU data residency

Classification routing

Tenant isolation (RLS)

Append-only audit log

GDPR-aligned processing

Screen Shield + Vault Lock

SOC 2 Type II

2027