PLATFORM · ARCHITECTURE · SECONDARY

Trust boundary inside your cloud account.

Secondary trust page — not the product you’re buying. The lead remains the 6-month embed; this page summarizes where the included platform runs when it’s in scope. Read the platform overview →

Serious platform engineering inside your cloud account — not a thin wrapper.

Customer cloud

Runs in the customer’s AWS account. Azure is fine when that’s their cloud. The trust boundary is their account — private subnets, ALB ingress, PrivateLink to AWS APIs.

Ingress paths

Webhook path for event-driven work, plus an optional scheduled-scan path. Pattern examples only — not a live warranty of any one SaaS connector.

Outbound LLM & SaaS

LLM calls go outbound over TLS to Anthropic. SaaS API calls go outbound from agents. Secrets live in the customer’s Secrets Manager / SSM.

Operator MCP

Plan first. Never auto-apply. The thin operator control plane wraps existing ops scripts; you confirm every apply and destroy.

We publish trust-boundary docs; implementation stays in your account.

Deeper reading → public security data-flow docs
Operator control

PLAN FIRST · never auto-apply

Human-gated operator MCP for Claude Desktop and Claude Code. Plans and manages the included platform in your AWS / Azure by wrapping our existing ops scripts. You confirm every apply.

Start with a working session

First call diagnoses CRM + process — then agents. Not a product demo. Not an install.

Book a working session Read platform