The Kre8iv family
Secure AI

Secure AI, built on the clouds you already trust.

Kre8ivTech designs and builds AI workflows on Amazon Bedrock, Gemini Enterprise Agent Platform (formerly Vertex AI), and Microsoft Foundry. The controls below are what each vendor documents about its own platform. A project uses a control only when that platform and that configuration are part of the build.

Platform controls

What these platforms document

Each statement is the vendor's, and each one links to the official page it comes from.

Amazon Bedrock

  • When you tune a foundation model, Amazon Bedrock bases it on a private copy of that model. AWS says that data is not shared with model providers and is not used to improve the base models. Amazon Bedrock security and compliance
  • AWS says your data is encrypted in transit and at rest. You can create, manage, and control encryption keys with AWS Key Management Service (AWS KMS). Identity-based policies can limit what users and roles can do, on which resources, and under what conditions. Amazon Bedrock security and compliance
  • You can use AWS PrivateLink to establish private connectivity from your Amazon VPC to Amazon Bedrock without exposing that VPC to internet traffic. Amazon Bedrock security and compliance
  • Amazon Bedrock Guardrails provides configurable safeguards to help detect and filter harmful content in prompts and model responses, including a prompt-attack category, to block or mask personally identifiable information, and to run contextual grounding checks that help detect hallucinations in responses that are not grounded in the source or are irrelevant to the user's query. Amazon Bedrock Guardrails user guide
  • Amazon Bedrock AgentCore is AWS's platform for production AI agents. Amazon Bedrock AgentCore

Gemini Enterprise Agent Platform (formerly Vertex AI)

  • Google's platform overview describes Gemini Enterprise Agent Platform (formerly Vertex AI) as an evolution of Vertex AI. Gemini Enterprise Agent Platform (formerly Vertex AI) overview
  • Google's machine-learning security controls page lists data residency at rest, customer-managed encryption keys (CMEK), VPC Service Controls, and Access Transparency as available for Gemini Enterprise Agent Platform (formerly Vertex AI) machine learning features. The same page says some security controls are not supported by Generative AI features, and that Vertex AI Feature Store and Vertex Data Labeling do not meet data-at-rest commitments. Security controls for machine learning services
  • A separate Generative AI security controls page lists support by model and feature, and says security controls are not supported for preview models. Security controls for Generative AI

Microsoft Foundry

  • Microsoft's current name for this platform is Microsoft Foundry. The previous names in Microsoft's own naming table are Azure AI Studio and Azure AI Foundry. What is Microsoft Foundry?
  • For Foundry Models sold by Azure in Microsoft Foundry, which include Azure OpenAI models, Microsoft says prompts, completions, embeddings, and training data are not available to other customers and are not available to OpenAI or other providers of those models. Data, privacy, and security for Foundry Models sold by Azure
  • For Foundry Models sold by Azure in Microsoft Foundry, which include Azure OpenAI models, Microsoft says that data is not used to train any generative AI foundation models without your permission or instruction. In the inference path, prompts and completions are not used to train, retrain, or improve the base models. Data, privacy, and security for Foundry Models sold by Azure
  • For Foundry Models sold by Azure in Microsoft Foundry, which include Azure OpenAI models, Microsoft says prompts and completions are evaluated in real time for harmful content types, and content generation is filtered based on configured thresholds. Microsoft documents that system as Guardrails (previously content filters). Data, privacy, and security for Foundry Models sold by Azure
  • Microsoft documents a private endpoint as a way to establish a private connection to a Foundry account and projects. Public network access can be disabled so access uses that private endpoint. That is a configuration option in the network isolation guide. Network isolation for Microsoft Foundry
How we build

How Kre8ivTech secures your AI

This is how we build. These are our practices, and they are separate from the vendor controls above.

  • Server-side input validation

    All input is validated on the server with a schema. A check that runs only in the browser is not enough on its own.

  • Secrets stay on the server

    The Supabase service-role key is used only in server code and is never shipped to the browser. Secrets are not committed to the repository.

  • Role checks before a server route acts

    A server route verifies the caller on the server and checks that caller's role before it acts.

  • Testing and security in how we build

    We include testing and security checks in how we build. We keep a change in progress while a testing or security check we run is still failing.

Next step

Talk to us about secure AI

Send a note through the contact form and tell us which system you want to build on.

Secure AI on Amazon Bedrock, Gemini Enterprise Agent Platform (formerly Vertex AI), and Microsoft Foundry — Kre8ivTech