Enterprise Security

Enterprise-Grade Security. Your Data, Your Control.

Deploy on your infrastructure, bring your own models, and maintain full control over every byte of data. OperativeOps was built for organizations that take security seriously.

Deployment

Self-Hosted & On-Premise

Run OperativeOps entirely within your own infrastructure. Data leaves your network only if you point an agent at a hosted model API — and that call goes through an egress gate you configure.

  • Docker Compose for single-node deployments
  • Kubernetes Helm charts for multi-node clusters
  • Air-gapped installation packages available
  • Self-hosted is the only deployment model — there is no hosted or managed tier
  • Your team manages updates on your schedule
Deployment Options

Docker Compose (single host)

Fastest to stand up

One host you already own. Outbound traffic only to the model endpoint and the systems you connect. Lowest operational burden.

Kubernetes (on-prem or your cloud account)

Scales with your cluster

Helm charts into your own cluster. Egress stays governed by your existing network policy; the model runtime is a hosted API or an in-cluster one. Your platform team operates it.

Air-gapped

No network egress

No egress at all. Model runs locally (Ollama, vLLM); updates arrive as signed offline bundles you install.

Supported Providers

OpenAI

GPT-4o, GPT-4o-mini

Anthropic

Claude 4, Sonnet

Groq

Llama 3.3, Mixtral

Azure OpenAI

Any deployed model

AWS Bedrock

Claude, Titan

Self-Hosted

Ollama, vLLM, TGI

Bring Your Own Model

Use Any LLM Provider

Do not be locked into a single AI provider. OperativeOps supports a provider-agnostic architecture — swap models without changing your workflows.

  • Switch providers per agent or per environment
  • Run fully offline with self-hosted models (Ollama, vLLM)
  • Use your existing enterprise AI agreements
  • No data sent to third parties when self-hosting

Data Protection

Encrypted Everywhere

Encryption at Rest

Data is stored in your own database and object storage using AES-256 encryption. Keys stay in your KMS — there is no external store holding a copy.

  • AES-256 encryption standard
  • Keys held by you, in your own KMS
  • Encrypted backups
  • Secure key rotation

Encryption in Transit

TLS 1.3 for all API and agent communications. Certificate pinning available for on-premise deployments.

  • TLS 1.3 enforced
  • Certificate pinning support
  • mTLS for service-to-service
  • HTTP/2 with ALPN

Access Control

Fine-Grained RBAC

Six predefined roles with granular permissions. Integrate with your existing identity provider via SSO/SAML.

  • SSO/SAML 2.0 integration (Okta, Azure AD, OneLogin)
  • SCIM provisioning for automated user sync
  • IP allowlisting and session management
  • Audit logs for every access event
Role-Based Access Control

Owner

Full control of the deployment, licence, and member management

Admin

Manage agents, integrations, and team settings

Manager

View all agents and insights, manage team conversations

Member

Chat with agents, view dashboards and insights

Viewer

Read-only access to dashboards and reports

API-Only

Programmatic access with scoped permissions

Compliance

Compliance Posture

Stated plainly, so nothing has to be taken on trust: what is certified, what is not, and where the responsibility sits in a self-hosted deployment.

Certifications held

None

OperativeOps holds no SOC 2, ISO 27001, ISO 42001 or BSI C5 attestation, and does not claim one. Those attestations certify an operated service — there is no operated service here.

Your certification scope

Inherited

Because the deployment runs inside your environment, it sits within your existing ISO 27001, BSI C5 or IT-Grundschutz scope. You keep the control evidence — no third-party audit report to adopt.

GDPR / DSGVO

By deployment

You remain the controller. No data is processed by a third party unless you configure an outbound model API — in which case that provider, not OperativeOps, is the processor you contract with.

EU AI Act

Supported by design

Record-keeping and traceability duties are supported in the product: an append-only audit ledger of every model decision, source citations on answers, and per-agent permission scope.

AI Governance Dashboard

Audit Trail

Every agent query, response, and data access logged

Prompt Injection Detection

Multi-layer input sanitization and monitoring

Output Filtering

PII redaction, hallucination detection, tone guardrails

Data Lineage

Trace every insight back to its source documents

Usage Analytics

Token usage, latency, and cost tracking per agent

AI Governance

Responsible AI, Built In

Every interaction with OperativeOps agents is logged, auditable, and traceable. The platform defends against prompt injection, unsupported answers, and data leakage at every layer — inside your perimeter, on logs only you can read.

  • Full audit trails with exportable logs
  • Prompt injection prevention at input and output layers
  • Automatic PII detection and redaction options
  • Data lineage tracking for all agent insights
  • Role-based access to AI governance dashboard

Air-Gapped Deployment

For the most security-sensitive environments, OperativeOps supports fully air-gapped installations. No internet connectivity required after initial setup — run entirely offline with self-hosted LLMs.

Offline Installers

Pre-packaged Docker images and Helm charts

Local LLMs

Run Llama, Mistral, or any GGUF model locally

Signed Packages

SHA-256 verified installation packages

Ready to Secure Your AI Infrastructure?

Send your security requirements — network egress, model runtime, key management, audit retention — and get the deployment documentation that answers them.