Trust

Built to pass your security review.

Where it runs, how your data is kept apart, and what it can prove.

Deployment

SaaS, VPC or on‑prem. The same product.

01 SaaS

aXentic cloudaXentic runtimeYour data · own tenant

Managed by us, isolated per tenant.

02 VPC

Your cloud accountaXentic runtimeYour data

Deployed inside your network boundary.

03 On-prem

Your infrastructureaXentic runtimeYour dataSelf-hosted model

Fully offline if you need it.

No feature cliffThe on-prem build is the same build. Governance, audit and the runtime behave identically wherever it runs.

Security

The controls your security review will ask for.

01 Identity and access

  • OIDC / SAML single sign-on, one realm per tenant
  • Roles and tenant claims carried in the token
  • Per-document knowledge ACLs
  • Per-agent knowledge scoping

02 Secrets

  • Vault-backed storage for LLM keys and connector secrets
  • Scoped tenant → workspace → project
  • Agent credentials held apart from provider keys

03 Tenant and data isolation

  • A Postgres schema per tenant — a database boundary, not app-level filtering
  • Every API call resolves its tenant before it touches data
  • Tenant erasure is one clean operation
  • Restricted data is held back from any model provider that retains prompts

04 Audit and observability

  • Append-only audit events, protected by database triggers
  • Hash-chained, so a missing or altered row is detectable
  • Work-graph provenance across every domain
  • OpenTelemetry traces and metrics

Compliance

Readiness, stated operationally.

EU AI ActIn scope, owned, evidencedWhich systems are in scope, who owns them, and how a decision was reached.
US statesWhat did it do?The record of what the system did, and the means to show it.
NIST AI RMFGovern, map, measure, manageOwnership, autonomy limits, monitoring and a reproducible record.
GDPRErasure at two grainsSubject data goes; the decision record stays, with the subject unlinked.
HIPAAPHI-awareAnything derived from patient data inherits its tier.

In place

  • A database schema per tenant
  • Append-only, hash-chained audit trail
  • OIDC / SAML single sign-on

Not yet certified

  • SOC 2
  • ISO 27001

None of the regimes above is a certification claim. Have a questionnaire?

Send it to us →