Tara Cloud-hosted GPUs in Japan
Training and inference compute runs on Tara Cloud-hosted infrastructure physically located in Japan.
Security & Compliance
Banks and financial institutions adopt generative AI only when they can answer the hard questions: where does the data live, who can reach it, and how is it audited? This page documents how Tara Cloud answers them — engineered into the platform, not bolted on.
Detailed documentation — security questionnaire responses, audit reports, and BCP plans — is available under NDA.
Data residency
On Tara Cloud-hosted infrastructure, GPU compute, open-weight LLM inference, and all customer data are processed and stored in Japan. Frontier models (OpenAI, Anthropic) are served through the vendors' official APIs; their inference may occur outside Japan — see the LLM API Endpoint page for details.
For regulated workloads, there is no cross-border transfer — a contractual commitment, not a configuration option.
Training and inference compute runs on Tara Cloud-hosted infrastructure physically located in Japan.
Open-weight model inference is processed on Japanese endpoints and stays in the country.
Customer data is stored and processed within Japanese borders on Tara Cloud-hosted services.
Data handling
Tara Cloud makes explicit, contractual commitments about how customer data is handled across every service line.
Customer data — prompts, completions, and artifacts — is never used to train or fine-tune shared models.
LLM API traffic can be processed in zero-retention mode, where nothing is logged or persisted.
On contract termination, data deletion follows a documented, executed procedure with attestation.
Tenant isolation
Regulated workloads run on infrastructure that is exclusively yours.
Regulated workloads run on dedicated, single-tenant GPU environments.
VPC peering and private endpoints connect your systems without traversing the public internet.
Regulated workloads share no compute, storage, or network resources with other customers.
Security architecture
Every layer of the platform is engineered and monitored to an institutional standard.
TLS 1.2 or higher on every connection.
AES-256 for all stored customer data.
Workloads isolated by security zone and policy.
MFA required for all administrative access.
Enterprise identity federation for your team.
Least-privilege access for every user and role.
Auditability
Your security team should never have to wonder what happened in your environment. Tara Cloud records it.
Infrastructure and API activity are logged end to end, from provisioning to inference.
Logs export to your SIEM for correlation, alerting, and investigation.
Audit records are protected against modification and deletion.
Compliance posture
Our security program is validated against international and Japanese frameworks. Reports are available under NDA.
Information security management system registered to ISO/IEC 27001.
Independently audited SOC 2 Type II report available under NDA.
Registered with Japan's Information system Security Management and Assessment Program.
Personal information handling aligned with Japan's Act on the Protection of Personal Information.
Architecture aligned with the safety guidelines of the Center for Financial Industry Information Systems.
Resilience
Availability is a security property. Your workloads are designed for continuity in every scenario.
Compute is distributed across redundant availability zones within Japan.
A business continuity plan defines recovery targets and procedures for every service.
Specific RTO and RPO commitments are shared with customers under NDA.
Support that operates like a partner — reachable, accountable, and Japanese-language fluent.
Enterprise agreements include 24/7 Japanese-language support, with English available on request.
A dedicated technical account manager who knows your environment and your roadmap.
Contractual incident-response commitments, monitored and reported.
The documentation your vendor assessment and legal teams need — ready when you are.
Detailed responses to your vendor security assessment, on your schedule.
A master services agreement structured for institutional buyers.
Certificates of insurance available on request.
Tell us about your workloads, data requirements, and compliance constraints. A senior security engineer will respond within one business day.