Your data stays in your environment. We deploy in your tenant/VPC (AWS/Azure/GCP) or a private cloud you control, with encryption in transit (TLS 1.2+) and at rest (AES-256). Access is gated by SSO/SAML and RBAC with least-privilege scoped connectors; all actions are logged for audit and replay. We honor data residency, support private networking (peering/VPN), and do not train foundation models on your data unless you opt in.