Security & compliance

Built for the procurement review.

LibraryOS Pro is designed to pass an institutional security and privacy assessment — with the controls libraries and their IT teams actually ask about.

Your data stays in the building

Run entirely on-premise and route inference to a local LLM (LM Studio) with a privacy-first mode — patron data and conversations never have to leave your network.

Tenant isolation & RBAC

Every request is scoped by a signed tenant claim; cross-tenant access is refused. Roles (super / admin / user) gate who can change configuration.

Tamper-evident audit trail

Every write-back action and every approval is recorded to a shared audit log you can export and analyse.

Data-subject rights (GDPR)

Export, erase and retention runs are built in as governed jobs, with exports delivered via presigned storage.

Prompt-injection defense

Untrusted patron input is scanned and quarantined before it reaches a model; untrusted XML is parsed safely.

PCI-safe payments

Fines are paid through Stripe hosted checkout; the ledger is written only from signature-verified webhooks.

Signed connector catalog

The connector marketplace catalog is HMAC-signed, and marketplace secrets are redacted from responses.

Full observability

OpenTelemetry traces, Prometheus metrics and Grafana dashboards, plus a per-run AI execution trace.

Procurement-ready

Answers for the security questionnaire.

Deploy on your own infrastructure, keep inference local, and bring a data-processing agreement to the table. We give your IT and privacy teams the specifics they need.

On-premiseLocal LLMRBACTenant isolationAudit trailGDPR export & erasePCI-safe paymentsSigned catalogOpenTelemetryDPA available
Ready when you are
Bring it to your review.

We'll walk your IT and privacy teams through the controls, on your own deployment.

Talk to us