Multi-Layer Security Architecture.

Polygraf operates simultaneously across four distinct interception layers — OS, API, communication, and document — ensuring no sensitive data escapes, regardless of path.

Coverage

Four Interception Layers.

Every path sensitive data can take is covered. Polygraf sits between the user and the destination at every layer simultaneously.

OS Layer

Desktop Overlay

API Layer

Secure LLM

Communication Layer

Meeting Guard

Document Layer

Secret Marker

Control Plane

Governance Dashboard

All layers report here — policies, alerts, audit logs

Data Flow

How Data Flows Through Polygraf

From the moment a user acts to the moment a response returns — every step protected.

STEP 1

User Action

User types, pasters, or uploads content containingsensitive data

Intercept

Polygraf intercepts at the appropriate layer before any transmission occurs

Classify

SLM identifies entity types with context-aware detection — 49+ entity types

Policy Check

Cross-reference with org policies — allow, block, or anonymize based on group/role rules

Anonymize

PII replaced with reversible tokens e.g. [PERSON_1], [SSN_1] — original data never transmitted

Process

Anonymized content sent safely to LLM or destination service

De-anonymize

Tokens replaced with originals in the response returned to user — seamless experience

Audit Log

Full event logged to Governance Dashboard for compliance reporting

Design Principles

Zero-Trust by Default.

No data leaves the perimeter

All SLMs run on-premises. Zero external API calls for processing.

No single point of failure

Each layer operates independently. One component down does not disable others.

Least privilege by default

Policies default to deny-all. Access is explicitly granted per group, role, and entity type.

Immutable audit trail

Every event is cryptographically signed and stored in tamper-evident logs.

Air-Gap Deployment Model

All components containerized (Docker/K8s)

No external dependencies

On-premises SLM inference

Zero outbound network calls

Local Governance Dashboard

No cloud telemetry

Offline model updates

Via signed package delivery

FAQ

Architecture Questions

Does Polygraf require agents installed on every endpoint?

The Desktop Overlay requires a lightweight client on endpoints. Secure LLM, Meeting Guard, and Secret Marker are agentless — they operate at the network/API level or via integration hooks. Most organizations deploy selectively based on their highest-risk surfaces first.

Each layer supports configurable fail-open or fail-closed modes. In fail-open, traffic flows through unimpeded while alerting your team. In fail-closed, interactions are blocked until the system recovers. The mode is set per-layer and per-policy.

Yes. The Governance Dashboard exports events via syslog, webhooks, and native integrations for Splunk, Microsoft Sentinel, IBM QRadar, and other major SIEMs. All log formats are configurable.

Yes. Policies are configurable at the org, department, group, and individual user level. Each policy can have its own entity types, thresholds, and enforcement actions.

Polygraf ships as a Helm chart. Each component (Secure LLM proxy, Secret Marker scanner, Meeting Guard listener, Governance Dashboard) deploys as independent pods with configurable resource limits. Horizontal scaling is supported.

For the Secure LLM proxy layer, average added latency is under 80ms measured on standard server hardware. Desktop Overlay adds imperceptible latency (<20ms) at the OS level. Meeting Guard operates asynchronously and does not add latency to the call.

Request an Architecture Review

We'll walk your security team through the full technical design

Products

thank you

Your download will start now.

Thank you!

Please provide information below and
we will send you a link to download the white paper.