Enterprise-Grade Security. Your Data, Your Control.
Deploy on your infrastructure, bring your own models, and maintain full control over every byte of data. OperativeOps was built for organizations that take security seriously.
Deployment
Self-Hosted & On-Premise
Run OperativeOps entirely within your own infrastructure. Data leaves your network only if you point an agent at a hosted model API — and that call goes through an egress gate you configure.
- Docker Compose for single-node deployments
- Kubernetes Helm charts for multi-node clusters
- Air-gapped installation packages available
- Self-hosted is the only deployment model — there is no hosted or managed tier
- Your team manages updates on your schedule
Docker Compose (single host)
Fastest to stand upOne host you already own. Outbound traffic only to the model endpoint and the systems you connect. Lowest operational burden.
Kubernetes (on-prem or your cloud account)
Scales with your clusterHelm charts into your own cluster. Egress stays governed by your existing network policy; the model runtime is a hosted API or an in-cluster one. Your platform team operates it.
Air-gapped
No network egressNo egress at all. Model runs locally (Ollama, vLLM); updates arrive as signed offline bundles you install.
OpenAI
GPT-4o, GPT-4o-mini
Anthropic
Claude 4, Sonnet
Groq
Llama 3.3, Mixtral
Azure OpenAI
Any deployed model
AWS Bedrock
Claude, Titan
Self-Hosted
Ollama, vLLM, TGI
Bring Your Own Model
Use Any LLM Provider
Do not be locked into a single AI provider. OperativeOps supports a provider-agnostic architecture — swap models without changing your workflows.
- Switch providers per agent or per environment
- Run fully offline with self-hosted models (Ollama, vLLM)
- Use your existing enterprise AI agreements
- No data sent to third parties when self-hosting
Data Protection
Encrypted Everywhere
Encryption at Rest
Data is stored in your own database and object storage using AES-256 encryption. Keys stay in your KMS — there is no external store holding a copy.
- AES-256 encryption standard
- Keys held by you, in your own KMS
- Encrypted backups
- Secure key rotation
Encryption in Transit
TLS 1.3 for all API and agent communications. Certificate pinning available for on-premise deployments.
- TLS 1.3 enforced
- Certificate pinning support
- mTLS for service-to-service
- HTTP/2 with ALPN
Access Control
Fine-Grained RBAC
Six predefined roles with granular permissions. Integrate with your existing identity provider via SSO/SAML.
- SSO/SAML 2.0 integration (Okta, Azure AD, OneLogin)
- SCIM provisioning for automated user sync
- IP allowlisting and session management
- Audit logs for every access event
Owner
Full control of the deployment, licence, and member management
Admin
Manage agents, integrations, and team settings
Manager
View all agents and insights, manage team conversations
Member
Chat with agents, view dashboards and insights
Viewer
Read-only access to dashboards and reports
API-Only
Programmatic access with scoped permissions
Compliance
Compliance Posture
Stated plainly, so nothing has to be taken on trust: what is certified, what is not, and where the responsibility sits in a self-hosted deployment.
Certifications held
NoneOperativeOps holds no SOC 2, ISO 27001, ISO 42001 or BSI C5 attestation, and does not claim one. Those attestations certify an operated service — there is no operated service here.
Your certification scope
InheritedBecause the deployment runs inside your environment, it sits within your existing ISO 27001, BSI C5 or IT-Grundschutz scope. You keep the control evidence — no third-party audit report to adopt.
GDPR / DSGVO
By deploymentYou remain the controller. No data is processed by a third party unless you configure an outbound model API — in which case that provider, not OperativeOps, is the processor you contract with.
EU AI Act
Supported by designRecord-keeping and traceability duties are supported in the product: an append-only audit ledger of every model decision, source citations on answers, and per-agent permission scope.
Audit Trail
Every agent query, response, and data access logged
Prompt Injection Detection
Multi-layer input sanitization and monitoring
Output Filtering
PII redaction, hallucination detection, tone guardrails
Data Lineage
Trace every insight back to its source documents
Usage Analytics
Token usage, latency, and cost tracking per agent
AI Governance
Responsible AI, Built In
Every interaction with OperativeOps agents is logged, auditable, and traceable. The platform defends against prompt injection, unsupported answers, and data leakage at every layer — inside your perimeter, on logs only you can read.
- Full audit trails with exportable logs
- Prompt injection prevention at input and output layers
- Automatic PII detection and redaction options
- Data lineage tracking for all agent insights
- Role-based access to AI governance dashboard
Air-Gapped Deployment
For the most security-sensitive environments, OperativeOps supports fully air-gapped installations. No internet connectivity required after initial setup — run entirely offline with self-hosted LLMs.
Offline Installers
Pre-packaged Docker images and Helm charts
Local LLMs
Run Llama, Mistral, or any GGUF model locally
Signed Packages
SHA-256 verified installation packages