Skip to content

Runs where the data already lives.

Proxara installs inside an AWS account the firm controls, or a private region built for it. The connectors, the device proxy, the classifier, and the signed record all stay inside it, and sensitive values are held before a prompt goes anywhere else.

The firm’s infrastructure, provisioned by Proxara.

Either shape is single tenant: one AWS account, isolated by the organization boundary, with nothing pooled across firms.

An account the firm owns

The same composition applies into the firm’s existing AWS organization. Its guardrails, its region, its keys, with Proxara running inside.

A private region, provisioned

Proxara vends a dedicated account through Account Factory, stands the whole stack up inside it, and runs it. No Terraform to learn, no infrastructure for the firm to operate.

Proxara does the provisioning and the running. The firm holds the keys and a read-only view, with no infrastructure work on its side.

The model that reads each prompt runs in the same account.

Classification happens inside the account. Sensitive values are swapped for tokens before they reach the tool an employee is using.

The default. A local model runs inside the account provisioned for the firm, in region. Nothing about the analysis leaves it, and nothing is retained or trained on.

See how redaction works
THE FIRM’S AWS ACCOUNTsingle tenant · one region · private subnetsEmployee+ AI toolEntryconnectors + proxyClassifierin-region modelRecordwrite-onceKMSthe firm’s keysuptime + healthno customer dataProxaracontrol plane

Isolation you can prove.

Not a policy page. Three things an auditor can check without taking anyone’s word for them.

A dedicated account

One AWS account per firm. The organization boundary is the isolation, and an auditor reads it straight from AWS.

Keys the firm holds

Encryption keys live in the firm’s own KMS. Proxara gets use, never administration, and the firm can pull that access in a single change.

A record that checks itself

Every entry is signed and chained. The trail verifies offline, without trusting Proxara to be honest about it.

Built to clear the security review.

Everything a security questionnaire asks for is already in the architecture.

No inbound path. The classifier and database sit in private subnets. Nothing reaches them from the open internet.

Write-once records. The audit archive lands in the firm’s own S3 under Object Lock, write-once and held for seven years.

Certificates that renew themselves. TLS is issued and rotated through ACM with DNS validation, never handled by hand.

A chain that re-checks itself. A scheduled job re-derives every signature each night and raises an alarm the moment one record will not verify.

Agents answer to the same region.

Coding agents and AI assistants pass the same checkpoint as every person. Each one lands on the register the moment it first acts, the firm can restrict it in one motion, and the refusal happens at the wire.

In a private deployment all of it stays inside the firm’s account: the register, the policy that restricts, and the signed record of every decision.

See agent governance
Proxara Console
console.proxara.ai/agents
ChatGPTClaudeGeminiProxara Console
Proxara
Coverage
AI Providers
Deployment
Telemetry
Agents
MCP & Connectors
Analysis
Intelligence
Compliance
Activity
Rox, Assistant
Settings
Online
Dana Whitfield
dana@meridian.co
Agent governance

Agents

Every individual agent on the register, recorded from its own traffic the moment it first appears. Each row is one agent with one owner, one home, and its own controls.

7D30D90D1Y
agents4owners3products3blocked1
Claude Code2 agentsProduct view
Claude Code · ws-4f2a91c3Delegated
Avery Chen · FIRM-LT-0142 · observed on the wire
4exchanges9actions25.7ktokensseen Jul 16, 10:24 AM
Claude Code · ws-b81d0c22Delegated
Jordan Lee · FIRM-LT-0077 · observed on the wire
214exchanges890actions413ktokensseen Jul 16, 09:58 AM
Cursor1 agentProduct view
Cursor · ws-9c31f0e4Delegated
Sam Ortiz · FIRM-LT-0103 · observed on the wire
96exchanges310actions128ktokensseen Jul 15, 04:41 PM
Codex CLI1 agentProduct view
Codex CLI · a91d44c0BlockedMachine
Ops automation · SRV-BUILD-02 · runs scheduled
41exchanges187actions96ktokensseen Jul 12, 02:03 AM
Window Jun 16, 2026 to Jul 16, 2026. Liveness and identity come from the durable register; counts are window bounded. Every record is content free.
10:25
One row per agent: owner, home, identity, activity

A coding agent caught, restricted, and refused at the wire.

Every account gets the same stack.

Network, keys, database, cache, compute, archive, and the alarms that watch them, stood up the same in every account.

1

AWS account per firm

0

shared data plane

4

keys the firm holds

7 yr

write-once retention

Everything Proxara does, in that one region.

The private deployment carries every surface. Same account, same keys, same record.

None of it asks to be taken on trust.

Three ways to check the region from outside it, in the order a security review works through them.

Put AI to work across the firm’s systems.

Tell us where the firm's data has to stay, and a person will reply.

Talk to us