Onboarding a limited number of private deployments this quarter. Request access →
← Security

Security architecture

Review the system you will actually deploy.

The Calliope AI security model depends on topology. BYOC, managed, on-premises, and air-gapped environments have different boundaries and operator responsibilities. The architecture should make those differences visible.

Six surfaces to review

01

Deployment topology

Identify which account and network hold the Workbench, workloads, management services, model endpoints, storage, telemetry, and evidence. Do not reuse a BYOC answer for a managed environment.

02

Network paths

Define user ingress, administrative access, private connectivity, model egress, data-source routes, update channels, and any support path. Apply customer network policy around the customer-owned environment.

03

Workload isolation

Use container and workspace boundaries, resource limits, storage scoping, and separate identities appropriate to the selected platform. Validate the controls against the workload rather than assuming one universal tenancy model.

04

Identity and privilege

Connect SSO through SAML or OIDC, assign RBAC, and inventory user, administrator, service, support, and model-provider credentials. Review privilege by role and topology.

05

Runtime and model control

Astrolift AI owns platform runtime concerns. Zentinelle AI owns agent-level observability and policy. Both are separate products from Workbench and should appear explicitly when included in the design.

06

Operations and evidence

Define patching, backup, incident response, access records, runtime telemetry, policy evidence, retention, and escalation ownership. The purchased support scope should name which responsibilities belong to Calliope AI.

Enterprises are scaling AI agents, data science, private LLMs and secure ML with Calliope AI

Self-host enterprise AI in days.

Stop choosing between moving fast and staying in control.

See how it works →