Skip to content

Nothing installs on anybody’s laptop.

One cloud account per firm, and three steps to switch it on. No installer, no certificate, and nothing to push to a fleet.

Pick the cloud the firm already uses.

The same deployment either way, in an account dedicated to one firm.

Amazon Web Services

The firm picks the account and the region.

Microsoft Azure

For firms already standardized on Microsoft.

Google Cloud

Coming soon.

How it gets deployed.

Four steps, and the firm does three of them. Nothing is installed on a device at any point.

Microsoft 365 is not connected

Connected work appears here once a Microsoft administrator approves the connection.

Set up the Microsoft 365 connection

Your Microsoft administrator approves this connection once. If that is not you, send them this link. It works once and stops working ten minutes after it was created.

Open the Microsoft approval pageCopy the link
01The console asks for one approval.
Reads only. Acting takes a separate approval.
  1. 01

    An administrator approves once

    One tenant-wide consent on Microsoft’s own screen. Every permission on it is delegated and read-only, and it is revoked from the firm’s own admin center.

    The page to hand whoever approves
  2. 02

    One address goes into the assistant

    The firm pastes a connector address into Claude or ChatGPT. There is no key to copy, no secret to store, and nothing to rotate later.

    The quickstart
  3. 03

    Employees sign in, and it is live

    Each person signs in once with the firm’s own Microsoft identity. Every read afterwards carries that person’s own access, so nobody sees more than they already could.

    What employees do
  4. 04

    Work activates a few kinds at a time

    The firm approves one kind of work, then another. Nothing installs on a device at any point, so there is no fleet rollout to schedule.

    How approved work is defined
ONE ENVIRONMENT, ONE FIRMprivate subnets, no default egressEmployee+ assistantConnectorsKarbon · M365Customer-localclassify · computeThe recordwritten as work runsKMSdedicated keyshealth and countsno customer contentProxaralifecycle only

Three things a reviewer opens and reads.

The account

One firm to an environment. The boundary is visible in the cloud console itself.

The keys

Storage is encrypted under dedicated keys. Proxara cannot delete or alter a key policy.

The record

An export opens in the reviewer’s own tools, not in ours.

Built to clear the security review.

What a questionnaire asks for is already in the architecture.

No inbound path. Compute and storage sit in private subnets, with no default route to the internet.

The gateway holds nothing. No source credential, no store permission, no mapping, no ability to act.

Write-once archives. Object Lock in compliance mode, for the term the firm’s own policy sets.

Exports are checked before they ship. One that does not verify is not served. Certificates are issued and rotated automatically.

What gets stood up in the account.

Ten parts, kept separate from each other on purpose, and the same ten in every firm.

What else to read.

The connections, the local planes, the private workspace, execution and the record. One account, one set of keys, one record.

Where the detail lives.

Three ways to check the region from outside it, in the order a security review works through them.

Put AI to work across the firm’s systems.

Tell us where the firm's data has to stay, and a person will reply.

Talk to us