Onboarding a limited number of private deployments this quarter. Request access →
← Security

Data protection

Protect the data by naming every destination.

Calliope AI separates the Workbench and workload data plane, model endpoints, support access, credentials, logs, and evidence so each can be reviewed against the requirements of the selected topology.

Data protection by boundary

01

Workload data plane

In BYOC, Workbench sessions, workload compute, and primary storage run in the customer AWS account. Managed and isolated deployments have different ownership and access paths that must be documented in the order and architecture.

02

Model destinations

Hosted model requests go directly to endpoints approved by the customer. Prompts and selected context are subject to the customer's agreement with that provider. Local endpoints keep inference inside the selected boundary.

03

Transport and storage protection

Use encrypted transport and encrypted storage appropriate to the deployment. In BYOC, the customer controls the cloud account, storage resources, key-management choices, and surrounding network policy.

04

Identity and access

Connect the Workbench to an approved identity provider and assign role-based access. Review customer administrators, Calliope AI support access, workspace users, and service identities separately.

05

Credentials

Keep model and data-source credentials in the deployment environment instead of copying them into notebooks or repositories. In BYOC, Calliope Labs Inc does not receive provider credentials.

06

Retention and deletion

Define retention separately for workspace files, application data, backups, access records, runtime telemetry, and optional Zentinelle AI evidence. Customer-controlled resources follow customer deletion and backup policy.

Enterprises are scaling AI agents, data science, private LLMs and secure ML with Calliope AI

Self-host enterprise AI in days.

Stop choosing between moving fast and staying in control.

See how it works →