Enterprise deployment track
Enterprise adds the deployment surface: dedicated VPC or bring-your-own-cloud, private networking over AWS PrivateLink or GCP Private Service Connect, SSO, single-tenant or on-premise deployment, a 4-hour initial response commitment, and a workload-outage SLA. We set the platform up with you.
How to read this page: we are an early-stage company and we label capabilities by how you get them today — self-service (works without us) or set up with us (we do it with your team during onboarding). We’d rather tell you which is which than let you find out mid-rollout.
What’s self-service vs. set up with us
Section titled “What’s self-service vs. set up with us”| Capability | How you get it today |
|---|---|
| Agents in coding agents, connectors, governed writes | Self-service (pilot track) |
| OAuth 2.1 / OIDC for the hosted endpoint | Self-service |
| SSO (SAML), SCIM provisioning | Set up with us |
| Dedicated VPC / bring-your-own-cloud | Set up with us |
| AWS PrivateLink / GCP Private Service Connect | Set up with us |
| Single-tenant or on-premise (including air-gapped) | Set up with us |
| MDM-managed install configuration | Set up with us |
| Approval gates on write agents | Included; configured together during onboarding |
Step 0 — Security review, before anything installs
Section titled “Step 0 — Security review, before anything installs”Most Enterprise onboarding starts in your security org, so here is the package to hand them:
- Architecture: on local installs, the brain — agents and all credentials — runs on your machines. We are not a SaaS that ingests your data: no credentials, warehouse data, query results, or PII touch our servers. Dedicated and on-prem deployments keep everything inside your boundary.
- Model spend and data: you bring your own model key at every level — including committed Anthropic, Bedrock, or Azure OpenAI spend. Inference never routes through us.
- Write safety: read agents cannot mutate systems. Write agents require explicitly enabled, write-scoped credentials, and on Enterprise every write sits behind an approval gate, with a receipt and audit trail on every change.
- Telemetry: documented in full at Usage data & telemetry — local installs send nothing; hosted surfaces collect usage counters only.
- Compliance status: SOC 2 Type II — in progress. We are pre-certification and we won’t imply otherwise. Current control posture and artifacts: Compliance status.
Checkpoint: your security team has reviewed the four pages linked above and knows which deployment shape you’re requesting.
Step 1 — Scoping call
Section titled “Step 1 — Scoping call”With your account team, decide:
- Deployment shape — hosted single-tenant, dedicated VPC in our cloud, your cloud (BYOC), or on-prem/air-gapped.
- Network path — public with OAuth, or PrivateLink / Private Service Connect.
- Identity — which IdP for SSO (SAML), whether SCIM provisioning is needed at day one.
- First workloads — which systems, which agents, what a successful first quarter looks like, in writing.
Checkpoint: a written onboarding plan with named owners on both sides and dates.
Step 2 — We deploy, together
Section titled “Step 2 — We deploy, together”Your deployment is set up with our team — typically: environment stood up → private networking established and tested → SSO federation verified with a pilot group → SCIM enabled → connectors configured with your least-privilege service credentials → live verification of every connection (the same 🟢-only-after-a-real-test rule as everywhere else — see Verify your setup).
Air-gapped installs follow the dedicated runbook in Deployment options.
Checkpoint: a pilot group signs in through your IdP, and every connected system reports 🟢 from inside your network boundary.
Step 3 — Roll out with controls on
Section titled “Step 3 — Roll out with controls on”- Approval gates: decide which agent write categories require which approvers. Irreversible actions (deletes, access grants, spend) always require approval — that floor is enforced in code and cannot be configured away.
- Audit: every governed write carries a receipt; audit trails are hash-chained and exportable to your SIEM.
- Seats: unlimited — roll out to the whole data org without a per-seat conversation.
Checkpoint: your admins can produce an audit trail for any agent write from the first week of use.
Support
Section titled “Support”Enterprise has a 4-hour initial-response commitment and a workload-outage SLA, alongside the named engineer relationship from Scale. Raise anything through your support channel, or file a bug or incident — incident filings are routed ahead of everything else.
What’s included, and what isn’t
Section titled “What’s included, and what isn’t”Included: everything in Scale, plus dedicated deployment, private networking, SSO/SCIM (set up with us), on-prem/air-gap options, 4-hour initial response, workload-outage SLA.
Not included: model inference (always your own key), and capabilities these docs don’t list — if you need something you don’t see, ask; “not yet” is an answer we give honestly.