Deployment & data residency

Your data stays in your tenant.
Wherever the platform runs.

Where it runs and who runs it are two separate questions, and you answer them independently. Whichever you choose, your data at rest stays in your own tenant, under your own keys.

In one line

Our cloud, your cloud account, or inside your perimeter with no external connectivity — in any combination across workflows. Most vendors offer one shape and ask you to fit it. We offer every shape, and the data never moves into ours.

Our runtime. Your tenant. Your keys.

Where it runs

Three ways to run it, compared on the questions a security review asks next.

Deployment model — side by side
Multi-tenant SaaSSingle-tenant VPCOn-premise, air-gapped
Runs inOur cloud, in the region your data-protection and residency requirements call forYour own cloud account — Google Cloud, Azure or AWSInside your perimeter, with no external connectivity
Your data at restYour tenant, your keysYour tenant, your keysYour tenant, your keys
What reaches our runtimeInteraction data only — encrypted in transit, not persistedThe runtime itself sits in your accountNothing leaves
UpdatesContinuousPeriodic updates and patchesPeriodic, packaged into your environment
SetupThe fastest start. First workflow live in four to six weeks in a templated sectorTypically three to five weeks of setupScoped with you — isolation takes longer to stand up
SuitsStarting without capital expenseData that cannot share infrastructure with anyone else’sA hard isolation requirement

And a fourth path: ownership. After implementation, the platform can be yours to keep and run under a perpetual licence — on your infrastructure, operated by your team, by us, or both.

What stays inside your boundary

Three things hold in every model. None of them is an option you pay extra for.

Data at rest

In your tenant, under your keys — SaaS included.

On SaaS the runtime is shared; your data at rest is not. What reaches the shared runtime is interaction data only, encrypted in transit and never persisted.

Models

Air-gapped means the models too.

On an air-gapped deployment the models run on your own resources — inside your VPC or on captive on-prem hardware — using open-weight models as needed. Nothing calls out.

Records

Your systems of record stay the source of truth.

We read from them and write back. We never become the system of record, so nothing about your records moves to make room for us.

Who runs it

A separate question, answered separately. Any of these works with any deployment model.

Who operates it
OptionWhat it means
We doForward-deployed engineers get it live and operate the workflow against the metric agreed in the contract.
Your team doesYour operations lead runs it day to day. No engineering team needed.
BothThe common shape. We run it; your operations lead owns the number.

What stays yours, whichever you choose

Everything built for you — workflows, integrations, business policies, escalation hierarchies, your data, your memory — is yours from day one, contractually, in your tenant, exportable in open formats.

What if CygnusAlpha goes away? Deployed on your infrastructure, the software keeps running, with source held in escrow and defined release triggers.

Security, and the limits we state up front

ISO 27001:2022 certified. SOC 2 Type II is in progress — if your process needs the report in hand before signature, tell us at the first conversation and we will sequence around it.

Boundary

Isolated deployments update periodically, not continuously.

VPC and air-gapped environments take packaged updates and patches on a schedule. Continuous release into an isolated environment is a promise we would not keep.

Boundary

Isolation adds setup time.

SaaS is the fastest start. A VPC typically adds three to five weeks; an air-gapped build is scoped with you. We say which before the contract, not after.

Boundary

Direct credentials still do what your systems permit.

Every automated path runs through the rulebook. A change made straight in a source system surfaces as our state disagreeing with it — detection, not prevention.

Which fits

Start from your first question
If your first question is…Start with
“How fast can we start?”Multi-tenant SaaS
“Our data can’t share infrastructure with anyone else’s.”A single-tenant VPC in your own cloud account
“Nothing leaves our network.”On-premise, air-gapped
“We need to own what we run.”Any of the above, with the path to ownership

Every capability, with an explicit yes or no — including the ones we do not offer. Platform capabilities →

Thirty-two answers on approval, rules, learning, data and commercials. Read the FAQ →

Agent platforms, integrators, build shops and outsourcers — compared on who runs it and who owns the outcome. How we compare →

If deployment is the question that decides it, start there.

Thirty minutes about fit — not a demo, not an audit, not a diagnostic. Bring your security team’s first three questions.

CygnusAlpha. We turn AI ambition into AI operations.