Trust is the architecture.

Security at aixplain starts at the infrastructure layer and extends through every agent execution. We do not train on your data. Session data is not retained unless you opt in. When you deploy on-prem or air-gapped, your data never leaves your perimeter.

Compliance and certifications

What we commit to. In writing.

SOC 2 Type I & II

Independently audited security, availability, and confidentiality controls on cloud deployments.

GDPR

Full compliance with European data protection regulation including data residency and subject rights.

PDPL (Saudi Arabia)

Personal Data Protection Law compliance for deployments serving Saudi and GCC enterprises.

No training on your data

Customer data is never used to train or improve any model, including aixplain's own. Ever.

Session data not retained

Session and inference data is not stored unless you explicitly opt in.

Audit trails on every action

Full execution trace per agent run: actions, tool calls, decisions, latency, cost, and errors.

Deployment sovereignty

Same runtime. Your terms.

Every deployment option runs the same aixplain OS. The only thing that changes is where your data lives and who manages the infrastructure.

Fully managed

Cloud

Fully managed infrastructure. Data encrypted at rest and in transit. SOC 2 Type II certified. Scales automatically without infrastructure overhead.

  • Encrypted at rest and in transit
  • SOC 2 Type II certified
  • Automatic scaling
  • Managed patching and updates
RUNS ON YOUR MACHINE

Desktop

Runs on your own machine. Your files, models, and data stay on the device — run local models with no cloud call, and reach aixplain Cloud when you need it.

  • Runs locally on your device
  • Local models, no cloud call
  • Your data stays on the machine
  • Cloud access when you need it
  • Full observability retained
AIR-GAPPED OR VPC

On-prem

Fully self-contained deployment within your perimeter — dedicated servers in your region, air-gapped or VPC. You own compliance, data, and the full deployment surface.

  • Dedicated regional servers
  • Air-gapped or VPC deployment
  • No external dependencies
  • Customer-owned compliance perimeter
  • Full data sovereignty

Three models. Same runtime. Your choice.

Cloud, on-prem, or hybrid. Same governance, same agents, same observability across all three.

CloudDesktopOn-prem
InfrastructureManaged by providerYour own machineFull control
ScalabilityAuto-scalingBound to your deviceLimited by hardware
LatencyHigherLocal, minimalLow
ComplianceProvider-dependentData stays on deviceFull control
Legacy integrationRequires middlewareLocal files and appsSeamless
Deployment speedNear-instantDownload and runRequires setup
Cost modelPay-as-you-goFree software, cloud pay-as-you-goHigh upfront, lower long-term
Vendor lock-inProvider-dependentNone (local, any model)None

Governance and control

Role-based access control

Members get roles that scope what they can see and change, at the workspace, model, tool, and data level.

Access and delegation

Agents run least-privilege, and you control which agents may delegate to which — authority never escalates on its own.

Action-level control

Define exactly what each agent can do, see, and output, scoped per agent, per deployment, per run.

Workspace isolation

Teams operate in isolated workspaces; keys, assets, and data never cross unless you share them.

Budgets and rate limits

Per-key and per-workspace rate limits stop abuse and runaway usage; budgets cap spend before it starts.

Audit and observability

Every action logged — actor, decision, tool call, cost — inspectable and exportable for compliance.

Security questions from your team?

We respond to enterprise security questionnaires and will walk your InfoSec team through our controls.