Skip to main content
Superatom is deployed entirely within customer infrastructure. All external communication is outbound HTTPS only. No inbound ports need to be opened.

Outbound Traffic

The platform makes two categories of outbound HTTPS calls: Both destinations can be routed through the organization’s existing forward proxy or firewall.
In air-gapped deployments with a self-hosted LLM, both outbound connections are eliminated. Zero data leaves the network perimeter.

What Never Leaves the Network

The following data categories are processed entirely within the customer’s infrastructure and never transmitted externally:
  • Raw data rows or individual records
  • PII or sensitive business data
  • Database credentials
  • Query results
  • File contents
  • User identities or conversation content

No Inbound Connections Required

Superatom requires no inbound ports to be opened. All external communication is initiated outbound by the platform. There are no webhooks, callbacks, or remote access channels.

Air-Gapped Deployment

For environments that cannot make any external calls, Superatom supports deployment with a self-hosted LLM running within the customer’s network. In this configuration:
  • Open-source or licensed models run on the customer’s GPU infrastructure
  • The Main Agent calls the LLM over the internal network
  • No external API calls are made
  • All telemetry is disabled or routed internally

What the LLM Receives

The LLM is a stateless inference service. Each request is constructed from scratch, and no state persists between calls.

Sent to the LLM

Never Sent to the LLM

The LLM receives only structural metadata: table names, column names, data types, and business definitions. It never receives the actual data stored in those tables.

No Training on Customer Data

Customer data, queries, and knowledge nodes are never used to train or fine-tune models. The LLM provider receives stateless inference requests only. This applies to both cloud-hosted and self-hosted LLM configurations.