Their cloud. Their keys. Their data.
Every instance runs in the customer's own project — with their encryption keys, their storage, and a full audit trail on every AI request.
Nothing leaves their project
Your app calls our engine. The engine reads and writes only inside the customer's cloud account.
What procurement teams ask for
Plain answers to the questions that block deals — not marketing claims.
Their keys, not ours
Encryption keys and service accounts stay in the buyer's cloud account — we never hold production keys unless explicitly contracted.
Documents stay in their storage
Files and search indexes live in dedicated buckets on the customer's project. No shared document pools.
One customer, one cloud
Each deployment gets its own GCP project or isolated environment. No cross-tenant data paths.
Audit trail for every AI call
Security teams can trace what was asked, what documents were retrieved, and what was sent to a model.
How tenants stay apart
Dedicated IAM, encryption, and network paths per customer deployment.
IAM guardrails
Dedicated service accounts per stack. GitHub Actions scoped to the customer project with least-privilege roles.
Customer-managed encryption
Optional CMEK for Cloud SQL and GCS on Dedicated Stack tiers. Keys rotate under the buyer's policy.
Private integration paths
ERP and internal tools connect inside the customer VPC. Sensitive graph data never transits through our infrastructure.
Traceability built in
Security teams can follow every question from request to document source to model response.
Request logging
Every chat request logged with timestamps, user context, and tool invocations — exportable for compliance reviews.
Source citations
Answers link back to the exact document passages used — so reviewers can verify what the model saw.
Approved content only
Responses come from indexed company documents — not the open web. You control what goes in.
Security review checklist
- task_altDedicated cloud project per customer instance
- task_altCustomer-owned encryption keys and Secret Manager
- task_altNo shared vector or document storage between tenants
- task_altFull audit trail on LLM and retrieval calls
- task_altNetwork egress controlled through customer VPC rules
- task_altDWU-first document retrieval for regulated product data (CPR 305/2011)
Need help with a security review?
Book an architecture review — we'll walk through your VPC, secrets, and data flow against our reference deployment.