Processing, by design.
Single-tenant by default. The runtime - orchestration, inference, vector store, retrieval, and audit log - runs inside your VPC on AWS, Azure, or on-prem. Air-gapped deployments are supported.
Nothing leaves
No prompt content, completions, embeddings, or telemetry cross the tenant boundary on any channel.
You hold the keys
Encryption at rest uses keys in your KMS or HSM. We configure the platform to use them; we never hold them.
No pipeline
Model weights are never updated on your content. The training pipeline simply does not exist in your tenant.
EU / US / UAE / on-prem
Choose where the deployment lives. Data residency follows your regulatory and contractual needs.
Short list
A deliberately small set of subprocessors, disclosed in the DPA. No standing access to your tenant.
Time-bound access
Support access is explicit, time-bound, and customer-approved - logged in the same audit trail as everything else.