Trust is the architecture.
Security at aixplain starts at the infrastructure layer and extends through every agent execution. We do not train on your data. Session data is not retained unless you opt in. When you deploy on-prem or air-gapped, your data never leaves your perimeter.
What we commit to. In writing.
SOC 2 Type I & II
Independently audited security, availability, and confidentiality controls on cloud deployments.
GDPR
Full compliance with European data protection regulation including data residency and subject rights.
PDPL (Saudi Arabia)
Personal Data Protection Law compliance for deployments serving Saudi and GCC enterprises.
No training on your data
Customer data is never used to train or improve any model, including aixplain's own. Ever.
Session data not retained
Session and inference data is not stored unless you explicitly opt in.
Audit trails on every action
Full execution trace per agent run: actions, tool calls, decisions, latency, cost, and errors.
Same runtime. Your terms.
Every deployment option runs the same aixplain OS. The only thing that changes is where your data lives and who manages the infrastructure.
Cloud
Fully managed infrastructure. Data encrypted at rest and in transit. SOC 2 Type II certified. Scales automatically without infrastructure overhead.
- Encrypted at rest and in transit
- SOC 2 Type II certified
- Automatic scaling
- Managed patching and updates
Desktop
Runs on your own machine. Your files, models, and data stay on the device — run local models with no cloud call, and reach aixplain Cloud when you need it.
- Runs locally on your device
- Local models, no cloud call
- Your data stays on the machine
- Cloud access when you need it
- Full observability retained
On-prem
Fully self-contained deployment within your perimeter — dedicated servers in your region, air-gapped or VPC. You own compliance, data, and the full deployment surface.
- Dedicated regional servers
- Air-gapped or VPC deployment
- No external dependencies
- Customer-owned compliance perimeter
- Full data sovereignty
Three models. Same runtime. Your choice.
Cloud, on-prem, or hybrid. Same governance, same agents, same observability across all three.
| Cloud | Desktop | On-prem | |
|---|---|---|---|
| Infrastructure | Managed by provider | Your own machine | Full control |
| Scalability | Auto-scaling | Bound to your device | Limited by hardware |
| Latency | Higher | Local, minimal | Low |
| Compliance | Provider-dependent | Data stays on device | Full control |
| Legacy integration | Requires middleware | Local files and apps | Seamless |
| Deployment speed | Near-instant | Download and run | Requires setup |
| Cost model | Pay-as-you-go | Free software, cloud pay-as-you-go | High upfront, lower long-term |
| Vendor lock-in | Provider-dependent | None (local, any model) | None |
Governance and control
Role-based access control
Members get roles that scope what they can see and change, at the workspace, model, tool, and data level.
Access and delegation
Agents run least-privilege, and you control which agents may delegate to which — authority never escalates on its own.
Action-level control
Define exactly what each agent can do, see, and output, scoped per agent, per deployment, per run.
Workspace isolation
Teams operate in isolated workspaces; keys, assets, and data never cross unless you share them.
Budgets and rate limits
Per-key and per-workspace rate limits stop abuse and runaway usage; budgets cap spend before it starts.
Audit and observability
Every action logged — actor, decision, tool call, cost — inspectable and exportable for compliance.
Security questions from your team?
We respond to enterprise security questionnaires and will walk your InfoSec team through our controls.