Your private LLM isn't the leak. The retrieval layer in front of it is. One normal question can surface a Board-Only memo.
That failure is the split screen in RAGGUARD, our runnable demo of the Sovereign RBAC Firewall, built on a fully synthetic European-bank fixture. On the left: a naive flat-ACL RAG, the build most pilots ship. Lena Vogt, an L2 credit analyst in that fixture, asks for the Q3 credit-loss projection. Years of nested-group inheritance debt make her transitively a "Board" member, and a flat ingestion-time tag has no concept of clearance. So the pipeline serves the Board Pack, the model reads out EUR 412 million, and the 🔴 LEAK banner lights up.
On the right: the same query, the same retrieval. A deterministic policy engine, outside any LLM, authorizes every candidate document at query time against her live group set and clearance. The Board memo is withheld before it ever reaches the model, with a machine-checkable reason code: BOARD_MEMBERSHIP_REQUIRED. The answer draws only on the two documents she is entitled to and says what was withheld and why.
Agents advise, code decides. This is the permission layer most enterprise RAG deployments lack. On the 40-case golden authorization set, the firewall scores 40/40 with zero unauthorized disclosures; the faithful flat-ACL baseline scores 29/40 with ten. Every serve and withhold lands in a hash-chained audit record inside your VPC. The 38-second Reel shows the leak and the catch side by side.
If you're a CISO or AI platform lead putting a private LLM through security review, we'd genuinely like to hear how retrieval-time permissions figure into it. The interactive demo is linked in the first comment. 🔒
#EnterpriseRAG #SovereignAI #PrivateLLM #AIGovernance #CISO
Published on Instagram · July 20, 2026
On social media