Deployment
Runs in your account.
Deployment architecture depends on the engagement. The platform is designed around your cloud account, your data boundary, and your control requirements — not a shared multi-tenant environment by default.
Reference architecture
What sits inside your cloud account.
Scroll to see the full diagram →
Customer Cloud Account
Everything below runs inside your cloud account and data boundary.
What this covers
Six things to confirm during design.
Data boundary
The platform is designed to operate within your data boundary rather than moving data to a separate managed environment. {{TBD: specific data flow diagram per engagement}}.
Architecture options
Runtime placement, network boundaries, and connectivity are confirmed during design against your cloud environment. {{TBD}}
Tool and data connectivity
Agents connect to your systems through scoped credentials configured for the specific workflow.
Network boundaries
Network access is limited to what a given agent's tools require. {{TBD: specific network architecture per engagement}}
Human review
Review surfaces are deployed alongside the runtime so reviewers see checkpoints without leaving your environment.
Operational ownership
Who owns monitoring, incident response, and change management is defined during production handover.
Precision, not promises
What we don't claim here.
We do not claim support for a specific cloud provider, certifications, or compliance standards on this page unless confirmed for your engagement. Where a detail depends on your environment, it's marked {{TBD}} rather than assumed.
For a full picture of security posture and current maturity, see the Trust page.
Walk through deployment for your environment.
Bring your cloud environment and data boundary requirements — we'll map the architecture against them directly.
