Trust is the architecture.

Security at aixplain starts at the infrastructure layer and extends through every agent execution. We do not train on your data. Session data is not retained unless you opt in. When you deploy on-prem or air-gapped, your data never leaves your perimeter.

Compliance and certifications

What we commit to. In writing.

SOC 2 Type I & II

Independently audited security, availability, and confidentiality controls on cloud deployments.

GDPR

Full compliance with European data protection regulation including data residency and subject rights.

PDPL (Saudi Arabia)

Personal Data Protection Law compliance for deployments serving Saudi and GCC enterprises.

No training on your data

Customer data is never used to train or improve any model, including aixplain's own. Ever.

Session data not retained

Session and inference data is not stored unless you explicitly opt in.

Audit trails on every action

Full execution trace per agent run: actions, tool calls, decisions, latency, cost, and errors.

Deployment sovereignty

Same runtime. Your terms.

Every deployment option runs the same aixplain OS. The only thing that changes is where your data lives and who manages the infrastructure.

Fully managed

Cloud

Fully managed infrastructure. Data encrypted at rest and in transit. SOC 2 Type II certified. Scales automatically without infrastructure overhead.

  • Encrypted at rest and in transit
  • SOC 2 Type II certified
  • Automatic scaling
  • Managed patching and updates
Data stays in region

On-edge

Dedicated servers deployed in your region. Data never crosses regional boundaries. aixplain provides the operational control plane only.

  • Dedicated regional servers
  • Data residency guaranteed
  • aixplain control plane only
  • Full observability retained
Air-gapped or VPC

On-prem

Fully self-contained deployment within your perimeter. Air-gapped or VPC. You own compliance, data, and the full deployment surface.

  • No external dependencies
  • Air-gapped or VPC deployment
  • Customer-owned compliance perimeter
  • Full data sovereignty

Three models. Same runtime. Your choice.

Cloud, on-prem, or hybrid. Same governance, same agents, same observability across all three.

CloudOn-edgeOn-prem
InfrastructureManaged by providerBalancedFull control
ScalabilityAuto-scalingScalable with constraintsLimited by hardware
LatencyHigherOptimized per workloadLow
ComplianceProvider-dependentCustomizableFull control
Legacy integrationRequires middlewareBest of bothSeamless
Deployment speedNear-instantModerateRequires setup
Cost modelPay-as-you-goBalancedHigh upfront, lower long-term
Vendor lock-inProvider-dependentFlexibleNone

Access controls

Identity & Access Management

IAM policies across models, agents, and data sources. Enforce least privilege at every layer.

Role-Based Access Control

RBAC policies at the workspace, model, tool, and data level. Granular and auditable.

Workspace Isolation

Teams operate in isolated workspaces with independent API keys, budgets, and rate limits.

Infrastructure-Level Enforcement

Access policies enforced at the infrastructure level, not the application level. No bypassing by design.

Bodyguard Micro-Agent

Every deployed agent runs with an embedded Bodyguard that intercepts unauthorized data access before execution.

Action-Level Scoping

Define exactly what each agent is allowed to do, see, and output. Scoped per agent, per deployment, per run.

Security questions from your team?

We respond to enterprise security questionnaires and will walk your InfoSec team through our controls.