Trust boundary inside your cloud account.
Secondary trust page — not the product you’re buying. The lead remains the 6-month embed; this page summarizes where the included platform runs when it’s in scope. Read the platform overview →
Serious platform engineering inside your cloud account — not a thin wrapper.
High-level data path
Ink Navy / Signal Blue / Paper only. No hop numbers, ports, or cloneable blueprint detail.
Internet → ALB → Orchestrator → Agents · inside Customer AWS / VPC / private subnets
Outbound via NAT to Anthropic & SaaS · PrivateLink to Secrets Manager / SSM
Runs in your account. Your trust boundary.
Summarized for buyers. Implementation stays in your account.
Customer cloud
Runs in the customer’s AWS account. Azure is fine when that’s their cloud. The trust boundary is their account — private subnets, ALB ingress, PrivateLink to AWS APIs.
Ingress paths
Webhook path for event-driven work, plus an optional scheduled-scan path. Pattern examples only — not a live warranty of any one SaaS connector.
Outbound LLM & SaaS
LLM calls go outbound over TLS to Anthropic. SaaS API calls go outbound from agents. Secrets live in the customer’s Secrets Manager / SSM.
Operator MCP
Plan first. Never auto-apply. The thin operator control plane wraps existing ops scripts; you confirm every apply and destroy.
We publish trust-boundary docs; implementation stays in your account.
Deeper reading → public security data-flow docsPLAN FIRST · never auto-apply
Human-gated operator MCP for Claude Desktop and Claude Code. Plans and manages the included platform in your AWS / Azure by wrapping our existing ops scripts. You confirm every apply.
Start with a working session
First call diagnoses CRM + process — then agents. Not a product demo. Not an install.