The firm's own cloud account, the firm's keys, and a revocable Proxara role.
Updated August 2026
For IT and security owners. Connect runs in one environment dedicated to one firm: the firm's own AWS account or Azure subscription, keys the firm administers, and a Proxara role the firm can revoke.
A dedicated account is isolation: no other firm shares the network, the database, or the keys. Isolation is not ownership, so every control below is recorded by name.
| Control | Recorded as |
|---|---|
| Account or subscription owner | The firm, or Proxara under contract |
| Root or tenant administration | Who holds it |
| Encryption keys | Who administers, who only holds use rights |
| The Proxara role | Its scope, and how the firm revokes it |
| Support access | What exists, who authorizes, where it is logged |
| Network paths | Every route in and out, and which planes have none |
| Model artifacts | Their origin, and how digests are verified |
| Exit | How to suspend, export, and have the system removed |
Two modes: the firm's own account with a revocable Proxara deployment role, or an explicitly contracted isolated managed account carrying the same written facts. The product states which is active, and never infers ownership from isolation.
| Plane | What it may reach |
|---|---|
| Raw processing and customer-contained inference | The firm's own stores and local models. No external model, no default internet egress. |
| External model gateway | Approved model endpoints only. No raw store, no mapping, no credential. |
| Execution workers | Only what a bound action needs, never a search surface over the firm's context. |
| Proxara operations | Content-free health only. No client content, prompts, artifacts, credentials, or keys. |
Each connected system is reachable only at the exact endpoints it requires.
One composition, in the firm's chosen region: private network, control and Work APIs, Work and domain-cell workers, document ingress, the privacy compiler, customer-contained inference, the external model gateway, the private workspace, execution and reconciliation workers, encrypted stores and queues, secrets and keys, content-free monitoring, and customer ingress with SSO.
AWS is the reference implementation, and Azure follows the same logical contracts: parity, not a weaker variant.
Beyond the firm's own connected systems, two things leave: content-free operational telemetry to Proxara, and the release package to the firm's own approved model endpoint.
Every field in a frame is a count, a version string, a percentile, or a category code, and no field exists that free text could travel in. Each frame is written to the Telemetry Ledger with its hash and its full payload, so the firm can open any row in the console and read the exact bytes.
No copy of the release package reaches Proxara.
Encryption at rest runs under keys the firm administers. Proxara's use rights are revocable, and administration never leaves the firm.
Releases are signed, and models inside the environment do not update themselves. The firm can verify the model artifact and its digest, its license and source, the serving image, and the revision it rolls back to.
The record is signed at source, and an export carries the signed bytes, the signatures, and the public keys, so a reviewer checks it with their own tools.
| To understand | Read |
|---|---|
| Every control, in one list | Security Overview |
| What a security team asks first | Connect security review |
| The processing terms | Data Processing Addendum |