Die Plattform
Xinity Runtime
Running AI on your own hardware does not outsource your duties. It makes them executable. This page states, across nine areas, what you own, what Xinity owns and what is genuinely shared.
Buying Xinity does not make you compliant. It makes your compliance provable.
Updated August 2026 · Runtime v0.23 · Apache 2.0 engine · Elastic License v2 dashboard
01
Who handles the hardware?
You own
·Procurement, physical security and access to the room
·Capacity, power, cooling and replacement
Xinity owns
✓Reference configurations and sizing guidance
✓Pilot hardware for the evaluation month (ASUS Ascent GX10)
Shared
Sizing for your workload is a joint exercise during the pilot.
02
Who handles OS hardening?
You own
·Base operating system and patching cadence
·CIS or BSI baselines, disk encryption
Xinity owns
✓Deployment artefacts that do not require weakened settings (Docker, NixOS flake in the repository)
✓Documentation of required ports and services
Shared
Xinity states what the software needs. You decide the baseline it runs on.
03
Who handles network controls?
You own
·Firewalling, segmentation and TLS termination
·The air-gap decision
Xinity owns
✓A runtime that makes no external calls during inference, verifiable in the gateway and daemon source
✓Documented model pull endpoints so they can be blocked or mirrored
Shared
For air-gapped installs you transport the model files. Xinity documents the offline path.
04
Who handles identity and access?
You own
·Your identity provider and SSO configuration
·Joiner, mover and leaver processes and role assignment
·Deciding who holds instance admin
Xinity owns
✓Role-based access control and SSO integration in the dashboard
✓Organisation-scoped API keys, applications and request logs
Shared
The role model is Xinity's mechanism. Its population is your policy. Whether the organisation scoping satisfies a specific isolation requirement is a judgment your team makes against readable source code.
05
Who handles logging and retention?
You own
·Retention rules for request and audit logs. The database runs on your infrastructure
·Log review and evaluation
Xinity owns
✓Request-level logging in the gateway, per key, application, organisation and model
✓Admin-action audit events including sign-ins, recording transport channel and real caller
✓Per-key logging toggle and audited deletion
Shared
The split matters: request logs sit in the open-source layer, admin audit events in the source-available dashboard.
06
Who handles model governance?
You own
·Which models run and who approves a model change
·Evaluation of each model for your use case
Xinity owns
✓A curated catalog with versioned model definitions and deployment controls
✓Model license terms shown in the dashboard, with deploys gated on restricted licenses
✓Audited model deployment actions
Shared
Model updates are your decision, executed through Xinity's mechanism.
07
Who handles vulnerability management?
You own
·Applying updates and tracking advisories for the operating system and adjacent stack
·Compensating controls until a patch is rolled out
Xinity owns
✓Private reporting, acknowledgement within five business days and assessment within fourteen days per SECURITY.md
✓Coordinated disclosure, GitHub advisories and prompt dependency updates
Shared
The patch is the project's job. Exposure assessment and rollout timing are yours.
08
Who handles incident response?
You own
·The incident response plan, forensics and decision authority
·Notification duties, including GDPR Article 33
Xinity owns
✓Advisory publication and patched releases
✓Audit trail and request logs as forensic inputs
Shared
The logs are Xinity-generated evidence inside a process you run.
09
Who handles EU AI Act classification?
You own
·Classification of each use case and deployer duties under Article 26
·Fundamental rights impact assessment under Article 27 for public-law bodies
Xinity owns
✓Architecture that produces the logging, access records and model inventory those duties rely on
Shared
The obligations never transfer. Standalone Annex III high-risk obligations apply from 2 December 2027 under Regulation (EU) 2026/1744, and Article 50 transparency duties have applied since 2 August 2026.
Why you can check this
Every claim in the Xinity column traces to the repository or to a published page: request logging in the gateway, audit events in the dashboard, the security policy in SECURITY.md. Where a judgment is yours to make, this page says so instead of making it for you. This page provides architecture and audit evidence, not legal advice.