Skip to content

Security & data

Everything runs in infrastructure you own. That is the security model.

No vendor tenancy, no resold API keys, no copy of your data on my side of the fence. The boundary is drawn below exactly as a security review will find it — and the review questions are answered in writing before you have to ask them.

The boundary

Where does the work run, and what does your data do?

Three zones. Everything that is built lives in the first, my access to it sits in the second and is yours to revoke, and only what an approved workflow has to send ever reaches the third.

Zone 1 · Yours

Your infrastructure — where everything lives

  • Your cloud account and automation platform
  • Your repositories — all source, prompts and runbooks
  • Your vector database and evaluation suites
  • Your model API keys, in your secret manager

Everything that is built lives here from day one. Nothing is hosted on a vendor tenancy, so there is nothing to migrate away from later.

Zone 2 · Delegated

My access — scoped and revocable

  • Delegated admin access, for the engagement only
  • Work lands in your version control, reviewably
  • Revocable by you in one click, at any time

Access is something you grant, watch and withdraw — not something the arrangement depends on you never checking.

Zone 3 · Providers you choose

Model providers — only what the workflow sends

  • Only the data the approved workflow has to send
  • To the providers you chose, on your own accounts
  • No-training-on-your-data configuration by default
  • Costs billed to you directly — never resold, never marked up

Before any build starts you receive a written one-page summary: which sub-processors, what is sent to each, where it is stored, how long it is retained, and how it is deleted.

Diligence

What a security review will ask, answered

The six questions procurement and security teams put to an automation vendor, answered here exactly as they are answered in an engagement.

Everything runs in your own tenancy — your cloud account, your automation instance, your vector database, your model API keys. That is deliberate on three grounds: you never lose access to your own operations if we stop working together, you see the real running cost directly rather than through my markup, and it keeps the arrangement clean under the licences of the tools involved.

On paper

The written commitments behind this page

A one-page data summary before any build starts — which sub-processors are involved, what is sent to each, where it is stored, how long it is retained, and how it is deleted. The privacy policy carries the sub-processor list, data residency and your rights; the terms carry ownership transfer and the AI-specific clauses.

Put these answers in front of your security team.

Forward this page, or bring the reviewer to the fit call — the architecture holds up to the questions, and hearing them early makes the engagement faster, not slower.

Prefer email? hello@soloz.ai