AI on your terms.
Self-host or private cloud. Audit logs. Custom domains. SAML SSO and SCIM provisioning. Everything you need to deploy AI without surrendering control.

Compliance, scale, and control.
Self-host
Or run on our cloud
Your infrastructure, dedicated private cloud, or managed.
SCIM 2.0
Provisioning
Plus SAML and OIDC SSO.
AES-256
Key encryption
Provider keys encrypted at rest.
CSV+JSON
Audit log export
Append-only, per organization.
Cloud. Private cloud. On-prem.
Self-host on your own infrastructure with Docker, Helm, or Kubernetes — or choose a dedicated single-tenant private cloud if you want managed ops without shared infrastructure. In any deployment model, you bring your own model API keys so your prompts and responses never transit a third-party AI gateway.
- Self-hosted (Docker, Helm, Kubernetes)
- Private cloud (dedicated single-tenant)
- Managed cloud (multi-tenant, isolated)
- Bring your own model keys in any mode

Fits your IdP.
Role-based access control, OAuth sign-in, SAML/OIDC SSO, and SCIM 2.0 provisioning are all available today — new hires get the right access from your IdP, and offboarding is automatic.
- Role-based access (admin, editor, user)
- Per-team subgroups
- OAuth sign-in (Google, GitHub, Microsoft)
- SAML/OIDC SSO and SCIM 2.0 provisioning

Receipts for every change.
Agent, workflow, connector, and admin changes are written to an append-only audit log that exports as CSV or JSON for your compliance team. Usage is metered per member and per model in admin analytics, and separate monthly spend quotas — set for the organization, a user, or a role — either warn or hard-block once the budget is hit. Provider API keys are encrypted at rest, and organization isolation is enforced at the database row level and verified in automated tests. IP allowlisting for admin access is on the enterprise roadmap.
- Append-only audit log, exportable as CSV or JSON
- Per-member, per-model metering; org and user spend quotas
- Provider keys encrypted at rest (AES-256-GCM)
- Per-org isolation enforced at the database layer

Read the full security architecture, current controls, and roadmap items.
Defensible AI at scale.
Self-host
Run on your own infrastructure.
Identity
SAML SSO and SCIM provisioning for enterprise IdPs.
Audit logs
Append-only, exportable per organization.
Usage governance
Per-org quotas, budgets, and analytics.
Custom domain
Your brand, your URL.
White-label
Your logo, colors, and domain.