Control
Self-hosted model, embedding or vector-store endpoint reachable without authentication
Every self-hosted inference, embedding and vector-store endpoint (Ollama, vLLM, llama.cpp server, Qdrant, Chroma, Weaviate and similar) either listens only on loopback or a private network that only the application reaches, or requires an API key or authenticating proxy; anonymous access is never enabled on a published port.
Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.
Reach
Trust and provenance
How far the rules this guard addresses have been checked. Each rule links to its provision, with its citation, official text and its own panel.
- This control
- Audit-grade: meets all 3 checks of the TwinEthos audit standard that apply to it.
- Lanes
- TwinEthos recommendation (not law) 1
- Data release
- Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.10. This page also reflects corpus changes made after that release; they ship in the next one.
- Legal review
- None of the 1 rule has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice.
- Audit standard
- 1 of 1 rule audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
- 1 detector, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
The guard to add
Bind self-hosted model and vector endpoints to loopback or a private network, or put an API key in front of them.
In docker-compose, Kubernetes manifests and start scripts, publish inference and vector-store ports only on 127.0.0.1 ("127.0.0.1:11434:11434") or keep them on an internal network the application alone reaches. Where a port must be reachable, require authentication: vLLM serve --api-key (or VLLM_API_KEY), llama-server --api-key, QDRANT__SERVICE__API_KEY, a Chroma server auth provider (CHROMA_SERVER_AUTHN_PROVIDER), Weaviate API-key or OIDC authentication with AUTHENTICATION_ANONYMOUS_ACCESS_ENABLED false, and for Ollama, which has no built-in authentication, an authenticating reverse proxy with the Ollama port itself unpublished.
Where it goes: 3 config and feature flags, 4 infrastructure-as-code, 6 API calls and integrations.
What reviewers look for: no compose service for ollama, vllm, qdrant or chroma publishing its port on all interfaces without an API key setting; no OLLAMA_HOST=0.0.0.0 ollama serve or vllm/llama-server --host 0.0.0.0 without --api-key in start scripts; Weaviate anonymous access off.
Example (docker-compose), before:
services:
ollama:
image: ollama/ollama
ports:
- "11434:11434"
qdrant:
image: qdrant/qdrant
ports:
- "6333:6333"After:
services:
ollama:
image: ollama/ollama
ports:
- "127.0.0.1:11434:11434" # loopback only; the app reaches it on the compose network
qdrant:
image: qdrant/qdrant
environment:
QDRANT__SERVICE__API_KEY: ${QDRANT_API_KEY}
ports:
- "127.0.0.1:6333:6333"Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.
Every rule this guard addresses
TwinEthos recommendation (not law) (1)
- Everywhere (*)
- Authenticate self-hosted model, embedding and vector-store endpoints TwinEthos derivation — guardrail.sec-authenticated-model-and-vector-endpoints
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.