Architecture & Infrastructure
AIPA Suite is designed from the ground up as a fully self-contained, on-premise software platform. Unlike cloud-dependent AI coding tools, every component of AIPA runs within your own infrastructure. no external server communication is required at any point during normal operation.
- All AI inference, code indexing, autocomplete and agent execution happen locally on your servers or developer workstations.
- No data is transmitted to AIPA servers, third-party APIs or any external endpoint. The application does not phone home.
- AIPA does not depend on cloud infrastructure from AWS, Azure, GCP or any other provider. Your IT team has full control of the deployment.
- Network access is only required for initial license activation and periodic license validation. Both can be performed via offline activation for air-gapped environments.
Data Privacy & Zero Telemetry
Protecting your source code and intellectual property is fundamental to AIPA's design philosophy. We enforce a strict zero-telemetry policy: no usage analytics, no crash reports, no behavioral tracking and no code snippets are ever collected or transmitted.
- Source code, prompts, completions and chat history are processed and stored exclusively on your local infrastructure.
- No telemetry, diagnostics or usage data is sent to AIPA or any third party. the application contains no tracking code whatsoever.
- AI model training with AIPA Tuning uses only local data; trained model weights remain on your servers and are never uploaded.
- When using external LLM providers (optional), you configure the connection directly. AIPA never acts as an intermediary or proxy for your prompts.
Air-Gapped & Offline Operation
AIPA was specifically engineered for classified, restricted and air-gapped environments where internet connectivity is unavailable or prohibited. Full functionality. including AI assistance. is available without any network connection.
- Runs entirely offline with local AI models (Ollama, llama.cpp, or any GGUF/ONNX-compatible model). No internet connectivity required after initial deployment.
- Offline license activation is available for environments where network access is not permitted. Licenses are validated using cryptographic signatures without contacting external servers.
- Deployment packages are available for manual installation via USB or internal repositories, including all dependencies and pre-configured local model bundles.
Compliance & Certifications
AIPA Suite is built to satisfy the requirements of the most demanding regulatory frameworks. Our architecture has been designed with compliance as a foundational requirement, not an afterthought.
- GDPR compliant by design. no personal data processing occurs outside your infrastructure, and no data is transferred to third countries.
- Compatible with ISO 27001 information security management requirements. AIPA can be deployed within your existing ISMS without exceptions.
- Supports ENS (Esquema Nacional de Seguridad) compliance for Spanish public-sector and regulated organizations.
- Architecture designed to satisfy the most stringent enterprise security audit requirements for confidentiality, integrity and availability.
- Suitable for deployment in environments subject to PCI DSS, HIPAA, NIS2 and defence-sector classification requirements.
Cryptographic License Security
AIPA uses a multi-layer cryptographic license system to protect against tampering, unauthorized distribution and license fraud.
- Each license is digitally signed using asymmetric cryptography. The application verifies the signature locally before activation.
- License tokens contain hardware-bound fingerprints that tie activation to specific machines, preventing unauthorized transfer.
- Periodic revalidation can be configured to operate offline using signed validation tokens, eliminating the need for network connectivity.
AI Model & Code Security
AI model operations in AIPA are sandboxed within your infrastructure. Whether you use built-in models, fine-tuned models via AIPA Tuning, or external providers, security boundaries are strictly enforced.
- Local models execute in isolated processes with no outbound network access. Model weights and inference data never leave the host machine.
- AIPA Tuning fine-tunes models exclusively on your hardware using your code and documentation. Training data and resulting weights remain on-premise.
- When optional external model providers are configured (e.g. OpenAI, Anthropic), the connection is direct from your infrastructure. AIPA does not proxy, log or store any prompts or responses.
- Code indexing for intelligent autocomplete and semantic search is performed locally using on-device vector databases. No embeddings are sent externally.
Audit & Governance
AIPA provides enterprise teams with the tools needed for full auditability and governance of AI-assisted development activities.
- The AIPA License Manager portal provides centralized visibility into license allocation, usage and seat management across your organization.
- Budget controls, team management and role-based access ensure that AI tool usage aligns with organizational policies.
- All license operations (activation, deactivation, transfer) are logged and auditable through the Client Zone admin panel.
Client Security
AIPA is built on top of the open-source Visual Studio Code (VS Code) editor maintained by Microsoft. Security advisories for VS Code are published on their GitHub security page. We regularly merge upstream security patches from the official microsoft/vscode repository to ensure AIPA benefits from the latest fixes.
- With each major VS Code release, we integrate the latest upstream code into AIPA, including all security patches and hardening improvements.
- Critical upstream security patches are cherry-picked and released immediately, without waiting for the next scheduled integration cycle.
Vulnerability Disclosure
If you believe you have found a security vulnerability in AIPA Suite, we encourage responsible disclosure. We are committed to acknowledging reports within 5 business days and addressing critical issues as a priority.
Please send reports to: {supportEmail}