Workload data plane
In BYOC, Workbench sessions, workload compute, and primary storage run in the customer AWS account. Managed and isolated deployments have different ownership and access paths that must be documented in the order and architecture.
Data protection
Calliope AI separates the Workbench and workload data plane, model endpoints, support access, credentials, logs, and evidence so each can be reviewed against the requirements of the selected topology.
In BYOC, Workbench sessions, workload compute, and primary storage run in the customer AWS account. Managed and isolated deployments have different ownership and access paths that must be documented in the order and architecture.
Hosted model requests go directly to endpoints approved by the customer. Prompts and selected context are subject to the customer's agreement with that provider. Local endpoints keep inference inside the selected boundary.
Use encrypted transport and encrypted storage appropriate to the deployment. In BYOC, the customer controls the cloud account, storage resources, key-management choices, and surrounding network policy.
Connect the Workbench to an approved identity provider and assign role-based access. Review customer administrators, Calliope AI support access, workspace users, and service identities separately.
Keep model and data-source credentials in the deployment environment instead of copying them into notebooks or repositories. In BYOC, Calliope Labs Inc does not receive provider credentials.
Define retention separately for workspace files, application data, backups, access records, runtime telemetry, and optional Zentinelle AI evidence. Customer-controlled resources follow customer deletion and backup policy.
Stop choosing between moving fast and staying in control.
See how it works →