Trust is the architecture.
Security at aixplain starts at the infrastructure layer and extends through every agent execution. We do not train on your data. Session data is not retained unless you opt in. When you deploy on-prem or air-gapped, your data never leaves your perimeter.
What we commit to. In writing.
SOC 2 Type I & II
Independently audited security, availability, and confidentiality controls on cloud deployments.
GDPR
Full compliance with European data protection regulation including data residency and subject rights.
PDPL (Saudi Arabia)
Personal Data Protection Law compliance for deployments serving Saudi and GCC enterprises.
No training on your data
Customer data is never used to train or improve any model, including aixplain's own. Ever.
Session data not retained
Session and inference data is not stored unless you explicitly opt in.
Audit trails on every action
Full execution trace per agent run: actions, tool calls, decisions, latency, cost, and errors.
Same runtime. Your terms.
Every deployment option runs the same aixplain OS. The only thing that changes is where your data lives and who manages the infrastructure.
Cloud
Fully managed infrastructure. Data encrypted at rest and in transit. SOC 2 Type II certified. Scales automatically without infrastructure overhead.
- Encrypted at rest and in transit
- SOC 2 Type II certified
- Automatic scaling
- Managed patching and updates
On-edge
Dedicated servers deployed in your region. Data never crosses regional boundaries. aixplain provides the operational control plane only.
- Dedicated regional servers
- Data residency guaranteed
- aixplain control plane only
- Full observability retained
On-prem
Fully self-contained deployment within your perimeter. Air-gapped or VPC. You own compliance, data, and the full deployment surface.
- No external dependencies
- Air-gapped or VPC deployment
- Customer-owned compliance perimeter
- Full data sovereignty
Three models. Same runtime. Your choice.
Cloud, on-prem, or hybrid. Same governance, same agents, same observability across all three.
| Cloud | On-edge | On-prem | |
|---|---|---|---|
| Infrastructure | Managed by provider | Balanced | Full control |
| Scalability | Auto-scaling | Scalable with constraints | Limited by hardware |
| Latency | Higher | Optimized per workload | Low |
| Compliance | Provider-dependent | Customizable | Full control |
| Legacy integration | Requires middleware | Best of both | Seamless |
| Deployment speed | Near-instant | Moderate | Requires setup |
| Cost model | Pay-as-you-go | Balanced | High upfront, lower long-term |
| Vendor lock-in | Provider-dependent | Flexible | None |
Access controls
Identity & Access Management
IAM policies across models, agents, and data sources. Enforce least privilege at every layer.
Role-Based Access Control
RBAC policies at the workspace, model, tool, and data level. Granular and auditable.
Workspace Isolation
Teams operate in isolated workspaces with independent API keys, budgets, and rate limits.
Infrastructure-Level Enforcement
Access policies enforced at the infrastructure level, not the application level. No bypassing by design.
Bodyguard Micro-Agent
Every deployed agent runs with an embedded Bodyguard that intercepts unauthorized data access before execution.
Action-Level Scoping
Define exactly what each agent is allowed to do, see, and output. Scoped per agent, per deployment, per run.
Security questions from your team?
We respond to enterprise security questionnaires and will walk your InfoSec team through our controls.