Onboarding a limited number of private deployments this quarter. Request access →

Trust Center

Give security an accurate data-flow answer.

In BYOC, Calliope AI Workbench and your workloads run in your account. Calliope Labs Inc does not receive or proxy your prompts, code, model responses, or provider credentials. Model requests go directly to the endpoints you approve, including local endpoints when zero egress is required.

The trust model

Your workload boundary stays yours. Model egress is explicit.

Private AI is not one universal topology. The right design depends on data classification, model choice, customer contracts, and who operates each part of the system. We document those boundaries instead of collapsing them into a slogan.

For BYOC, the Workbench and workload data plane run inside your cloud account, network, and region. Your IAM, storage, network policy, and logging remain part of the control environment. Calliope Labs Inc does not sit in the path of workload or model traffic.

If you choose a hosted model provider, prompts and context travel directly from your environment to that provider under your agreement with them. If the workload requires zero egress, use a local model or an endpoint inside the approved boundary.

  • Customer-owned data plane · Workbench sessions, workload compute, and storage run in the environment selected for the deployment.
  • No Calliope AI prompt proxy in BYOC · Workload payloads do not pass through Calliope Labs Inc systems.
  • Explicit model destinations · Your organization approves the endpoints allowed to receive model requests.
  • Customer-held credentials · Provider keys remain in the deployment environment and are not exposed to Calliope Labs Inc.
  • Zero-egress option · Keep inference local or inside the approved network boundary when external model traffic is not permitted.
See the security architecture →

Compliance status

Deployment topology is not certification.

Running Calliope AI inside an environment you already control can reduce the number of new data flows you must review. It does not transfer certifications or remove your obligations. The table below separates current Calliope AI status from the controls available in a customer deployment.

FrameworkStatusWhat it means for you
SOC 2 Type IIIn progressFormal attestation is not complete. Request the current security packet and available evidence for your review.
HIPAABAA on requestBYOC can keep Workbench and workload data inside your HIPAA-scoped environment. Model destinations still need to match your PHI policy and agreements.
GDPRControls alignedA DPA and subprocessor list are available. Select region, deployment topology, and model endpoints to meet your own residency and transfer requirements.
EU AI Act and NIST AI RMFControl mappings availableZentinelle AI evidence can be mapped to AI-specific logging, attribution, policy, and oversight requirements. A mapping is not a certification.
ISO 27001RoadmapNot currently certified. Security documentation can be reviewed against your supplier requirements.
PCI DSSNot certifiedA customer may scope BYOC inside its own PCI environment, subject to its architecture, assessor, and operating controls.
FedRAMPEvaluatingNo FedRAMP authorization is claimed. Public-sector and isolated deployment requirements are scoped with the customer.
Full compliance detail →

Bring the real architecture into the review.

Send the questionnaire and the proposed topology. An engineer can walk your reviewers through the workload boundary, model destinations, operator access, available evidence, and any controls that remain your responsibility.

Enterprises are scaling AI agents, data science, private LLMs and secure ML with Calliope AI

Self-host enterprise AI in days.

Stop choosing between moving fast and staying in control.

See how it works →