Skip to content

Enterprise deployment track

Enterprise adds the deployment surface: dedicated VPC or bring-your-own-cloud, private networking over AWS PrivateLink or GCP Private Service Connect, SSO, single-tenant or on-premise deployment, a 4-hour initial response commitment, and a workload-outage SLA. We set the platform up with you.

How to read this page: we are an early-stage company and we label capabilities by how you get them today — self-service (works without us) or set up with us (we do it with your team during onboarding). We’d rather tell you which is which than let you find out mid-rollout.

CapabilityHow you get it today
Agents in coding agents, connectors, governed writesSelf-service (pilot track)
OAuth 2.1 / OIDC for the hosted endpointSelf-service
SSO (SAML), SCIM provisioningSet up with us
Dedicated VPC / bring-your-own-cloudSet up with us
AWS PrivateLink / GCP Private Service ConnectSet up with us
Single-tenant or on-premise (including air-gapped)Set up with us
MDM-managed install configurationSet up with us
Approval gates on write agentsIncluded; configured together during onboarding

Step 0 — Security review, before anything installs

Section titled “Step 0 — Security review, before anything installs”

Most Enterprise onboarding starts in your security org, so here is the package to hand them:

  • Architecture: on local installs, the brain — agents and all credentials — runs on your machines. We are not a SaaS that ingests your data: no credentials, warehouse data, query results, or PII touch our servers. Dedicated and on-prem deployments keep everything inside your boundary.
  • Model spend and data: you bring your own model key at every level — including committed Anthropic, Bedrock, or Azure OpenAI spend. Inference never routes through us.
  • Write safety: read agents cannot mutate systems. Write agents require explicitly enabled, write-scoped credentials, and on Enterprise every write sits behind an approval gate, with a receipt and audit trail on every change.
  • Telemetry: documented in full at Usage data & telemetry — local installs send nothing; hosted surfaces collect usage counters only.
  • Compliance status: SOC 2 Type II — in progress. We are pre-certification and we won’t imply otherwise. Current control posture and artifacts: Compliance status.

Checkpoint: your security team has reviewed the four pages linked above and knows which deployment shape you’re requesting.

With your account team, decide:

  1. Deployment shape — hosted single-tenant, dedicated VPC in our cloud, your cloud (BYOC), or on-prem/air-gapped.
  2. Network path — public with OAuth, or PrivateLink / Private Service Connect.
  3. Identity — which IdP for SSO (SAML), whether SCIM provisioning is needed at day one.
  4. First workloads — which systems, which agents, what a successful first quarter looks like, in writing.

Checkpoint: a written onboarding plan with named owners on both sides and dates.

Your deployment is set up with our team — typically: environment stood up → private networking established and tested → SSO federation verified with a pilot group → SCIM enabled → connectors configured with your least-privilege service credentials → live verification of every connection (the same 🟢-only-after-a-real-test rule as everywhere else — see Verify your setup).

Air-gapped installs follow the dedicated runbook in Deployment options.

Checkpoint: a pilot group signs in through your IdP, and every connected system reports 🟢 from inside your network boundary.

  • Approval gates: decide which agent write categories require which approvers. Irreversible actions (deletes, access grants, spend) always require approval — that floor is enforced in code and cannot be configured away.
  • Audit: every governed write carries a receipt; audit trails are hash-chained and exportable to your SIEM.
  • Seats: unlimited — roll out to the whole data org without a per-seat conversation.

Checkpoint: your admins can produce an audit trail for any agent write from the first week of use.

Enterprise has a 4-hour initial-response commitment and a workload-outage SLA, alongside the named engineer relationship from Scale. Raise anything through your support channel, or file a bug or incident — incident filings are routed ahead of everything else.

Included: everything in Scale, plus dedicated deployment, private networking, SSO/SCIM (set up with us), on-prem/air-gap options, 4-hour initial response, workload-outage SLA.

Not included: model inference (always your own key), and capabilities these docs don’t list — if you need something you don’t see, ask; “not yet” is an answer we give honestly.