Security
Security starts with a real data-flow answer.
For BYOC, Calliope AI Workbench and your workloads run in your account. Hosted model requests go directly to the providers you approve. Local or in-boundary models keep inference inside the perimeter when zero egress is required.
What reviewers need
Separate topology, controls, and certification status.
Security Architecture
See where Workbench, workloads, control services, model endpoints, and operators sit in each deployment topology.
Explore →Data Protection
Review identity, network, storage, encryption, retention, and customer responsibility across the data lifecycle.
Explore →Compliance Status
See what is mapped, aligned, in progress, planned, or not certified without treating deployment location as an attestation.
Explore →Know which boundary applies to which traffic.
In BYOC, Calliope Labs Inc does not receive or proxy prompts, code, model responses, or provider credentials. Your selected model endpoint is a separate data destination. That distinction lets security approve external providers where permitted and require local inference where it is not.

