Your data stays in your tenant.
Wherever the platform runs.
Where it runs and who runs it are two separate questions, and you answer them independently. Whichever you choose, your data at rest stays in your own tenant, under your own keys.
In one line
Our cloud, your cloud account, or inside your perimeter with no external connectivity — in any combination across workflows. Most vendors offer one shape and ask you to fit it. We offer every shape, and the data never moves into ours.
Our runtime. Your tenant. Your keys.
Where it runs
Three ways to run it, compared on the questions a security review asks next.
| Multi-tenant SaaS | Single-tenant VPC | On-premise, air-gapped | |
|---|---|---|---|
| Runs in | Our cloud, in the region your data-protection and residency requirements call for | Your own cloud account — Google Cloud, Azure or AWS | Inside your perimeter, with no external connectivity |
| Your data at rest | Your tenant, your keys | Your tenant, your keys | Your tenant, your keys |
| What reaches our runtime | Interaction data only — encrypted in transit, not persisted | The runtime itself sits in your account | Nothing leaves |
| Updates | Continuous | Periodic updates and patches | Periodic, packaged into your environment |
| Setup | The fastest start. First workflow live in four to six weeks in a templated sector | Typically three to five weeks of setup | Scoped with you — isolation takes longer to stand up |
| Suits | Starting without capital expense | Data that cannot share infrastructure with anyone else’s | A hard isolation requirement |
And a fourth path: ownership. After implementation, the platform can be yours to keep and run under a perpetual licence — on your infrastructure, operated by your team, by us, or both.
What stays inside your boundary
Three things hold in every model. None of them is an option you pay extra for.
In your tenant, under your keys — SaaS included.
On SaaS the runtime is shared; your data at rest is not. What reaches the shared runtime is interaction data only, encrypted in transit and never persisted.
Air-gapped means the models too.
On an air-gapped deployment the models run on your own resources — inside your VPC or on captive on-prem hardware — using open-weight models as needed. Nothing calls out.
Your systems of record stay the source of truth.
We read from them and write back. We never become the system of record, so nothing about your records moves to make room for us.
Who runs it
A separate question, answered separately. Any of these works with any deployment model.
| Option | What it means |
|---|---|
| We do | Forward-deployed engineers get it live and operate the workflow against the metric agreed in the contract. |
| Your team does | Your operations lead runs it day to day. No engineering team needed. |
| Both | The common shape. We run it; your operations lead owns the number. |
What stays yours, whichever you choose
Everything built for you — workflows, integrations, business policies, escalation hierarchies, your data, your memory — is yours from day one, contractually, in your tenant, exportable in open formats.
What if CygnusAlpha goes away? Deployed on your infrastructure, the software keeps running, with source held in escrow and defined release triggers.
Security, and the limits we state up front
ISO 27001:2022 certified. SOC 2 Type II is in progress — if your process needs the report in hand before signature, tell us at the first conversation and we will sequence around it.
Isolated deployments update periodically, not continuously.
VPC and air-gapped environments take packaged updates and patches on a schedule. Continuous release into an isolated environment is a promise we would not keep.
Isolation adds setup time.
SaaS is the fastest start. A VPC typically adds three to five weeks; an air-gapped build is scoped with you. We say which before the contract, not after.
Direct credentials still do what your systems permit.
Every automated path runs through the rulebook. A change made straight in a source system surfaces as our state disagreeing with it — detection, not prevention.
Which fits
| If your first question is… | Start with |
|---|---|
| “How fast can we start?” | Multi-tenant SaaS |
| “Our data can’t share infrastructure with anyone else’s.” | A single-tenant VPC in your own cloud account |
| “Nothing leaves our network.” | On-premise, air-gapped |
| “We need to own what we run.” | Any of the above, with the path to ownership |
Every capability, with an explicit yes or no — including the ones we do not offer. Platform capabilities →
Thirty-two answers on approval, rules, learning, data and commercials. Read the FAQ →
Agent platforms, integrators, build shops and outsourcers — compared on who runs it and who owns the outcome. How we compare →
If deployment is the question that decides it, start there.
Thirty minutes about fit — not a demo, not an audit, not a diagnostic. Bring your security team’s first three questions.
CygnusAlpha. We turn AI ambition into AI operations.