Runs where the data already lives.
Proxara installs inside an AWS account the firm controls, or a private region built for it. The connectors, the device proxy, the classifier, and the signed record all stay inside it, and sensitive values are held before a prompt goes anywhere else.
The firm’s infrastructure, provisioned by Proxara.
Either shape is single tenant: one AWS account, isolated by the organization boundary, with nothing pooled across firms.
An account the firm owns
The same composition applies into the firm’s existing AWS organization. Its guardrails, its region, its keys, with Proxara running inside.
A private region, provisioned
Proxara vends a dedicated account through Account Factory, stands the whole stack up inside it, and runs it. No Terraform to learn, no infrastructure for the firm to operate.
Proxara does the provisioning and the running. The firm holds the keys and a read-only view, with no infrastructure work on its side.
The model that reads each prompt runs in the same account.
Classification happens inside the account. Sensitive values are swapped for tokens before they reach the tool an employee is using.
The default. A local model runs inside the account provisioned for the firm, in region. Nothing about the analysis leaves it, and nothing is retained or trained on.
See how redaction worksIsolation you can prove.
Not a policy page. Three things an auditor can check without taking anyone’s word for them.
A dedicated account
One AWS account per firm. The organization boundary is the isolation, and an auditor reads it straight from AWS.
Keys the firm holds
Encryption keys live in the firm’s own KMS. Proxara gets use, never administration, and the firm can pull that access in a single change.
A record that checks itself
Every entry is signed and chained. The trail verifies offline, without trusting Proxara to be honest about it.

Built to clear the security review.
Everything a security questionnaire asks for is already in the architecture.
No inbound path. The classifier and database sit in private subnets. Nothing reaches them from the open internet.
Write-once records. The audit archive lands in the firm’s own S3 under Object Lock, write-once and held for seven years.
Certificates that renew themselves. TLS is issued and rotated through ACM with DNS validation, never handled by hand.
A chain that re-checks itself. A scheduled job re-derives every signature each night and raises an alarm the moment one record will not verify.
Agents answer to the same region.
Coding agents and AI assistants pass the same checkpoint as every person. Each one lands on the register the moment it first acts, the firm can restrict it in one motion, and the refusal happens at the wire.
In a private deployment all of it stays inside the firm’s account: the register, the policy that restricts, and the signed record of every decision.
See agent governanceA coding agent caught, restricted, and refused at the wire.
Every account gets the same stack.
Network, keys, database, cache, compute, archive, and the alarms that watch them, stood up the same in every account.
AWS account per firm
shared data plane
keys the firm holds
write-once retention
Everything Proxara does, in that one region.
The private deployment carries every surface. Same account, same keys, same record.
None of it asks to be taken on trust.
Three ways to check the region from outside it, in the order a security review works through them.
Put AI to work across the firm’s systems.
Tell us where the firm's data has to stay, and a person will reply.
Talk to us


