Architecture · How it fits
PrimeSwarm fits your stack
PrimeSwarm is not a replacement for your LLM, your identity provider, your SIEM, or your document system. It is the governance gate that sits between them. You keep your existing providers. We add the gate, the receipts, and the human escalation.
User
Your employee
Governance Gate
10 layers · receipts · HITL
Your LLM
Azure / Bedrock / self-hosted
Sidecar connections
LLM providers
Azure OpenAI
PrivateLink / VNet injection
PHI and regulated data never traverses the public internet. The governance stack calls Azure OpenAI through your existing private endpoint.
AWS Bedrock
VPC endpoint
Cross-region inference through your existing VPC. Governance receipts include the model ARN and inference parameters.
Anthropic Claude
Direct API or AWS Bedrock
Prompt-injection defense and boundary enforcement run before the prompt reaches Claude.
Google Vertex AI
VPC peering / Private Service Connect
Gemini models called through your existing private connectivity.
Open-source models (Llama, Mistral)
Self-hosted / vLLM / Ollama
Governance stack runs in front of your self-hosted inference endpoint. No external API calls required.
Custom models
REST API
Any model exposing a chat-completions-compatible endpoint works. The governance stack is model-agnostic.
Identity & access
Okta
SCIM 2.0 / SAML
Role-based gating uses Okta groups and roles. User identity flows through SSO — no separate PrimeSwarm credentials.
Microsoft Entra ID (Azure AD)
SCIM / OAuth 2.0
Entra ID groups map to PrimeSwarm governance scopes. Conditional Access policies are respected.
Google Workspace
OAuth 2.0 / SCIM
Workspace groups and org units map to knowledge boundaries.
Ory (Kratos / Keto)
OIDC / OPA
Self-hosted identity. PrimeSwarm sits in front of Ory, not behind it.
Audit & SIEM
Splunk
HTTP Event Collector (HEC)
Every governance receipt is forwarded to Splunk in real time. Receipts include gate state, residual, model, prompt hash, and user identity.
Datadog
Logs API / Datadog Agent
Governance events as custom logs. Dashboards for gate state distribution, HITL escalation rate, and denial rate.
Elastic / ELK
Elasticsearch _bulk API
Receipts indexed as documents. Kibana dashboards for compliance reporting.
Sumo Logic
HTTP Source
Cloud SIEM integration. Governance receipts as structured log events.
IBM QRadar
Syslog / REST API
On-prem SIEM integration for regulated environments.
Custom SIEM
Webhook / REST
Any system that accepts JSON over HTTP can receive governance receipts.
Document & clinical systems
iManage
REST API
Legal document boundaries enforced. The agent cannot access documents outside the defined scope.
NetDocuments
REST API
Provenance receipts link to NetDocuments document IDs.
SharePoint
Microsoft Graph API
Knowledge boundaries map to SharePoint site permissions.
Epic Systems (EHR)
FHIR R4 / HL7
Clinical decision support with patient context from Epic. PHI redaction before the model sees the prompt.
Cerner / Oracle Health
FHIR R4
Clinical workflows with governed HITL escalation for high-stakes decisions.
Custom DMS
REST / filesystem
Any document system with an API or filesystem access can be a knowledge boundary.
Deployment
Your VPC (AWS, GCP, Azure)
Helm chart deploys to your Kubernetes cluster. HPA autoscaling. Your network controls, your security groups, your compliance boundary.
On-premises
For air-gapped or strictly regulated environments. Runs on any Kubernetes cluster or as a standalone binary with SQLite.
Private cloud
Dedicated cloud account under your billing. We configure it; you own it. No shared infrastructure.
Our VPC (Guard only)
Guard SaaS runs in our VPC. Your data stays in your tenant. Estate and Federation do not run in our VPC.
Don't see your stack?
PrimeSwarm is model-agnostic, identity-agnostic, and SIEM-agnostic. If your system has an API, we can integrate with it. Tell us what you run and we will map it.