Your data stays in your platform, and you can verify it
VaultSpeed runs the control plane as a managed single tenant service and holds metadata, never your data. This page lists what runs where, who is accountable, and the evidence you can verify today.
Where things run
Three ways to deploy
VaultSpeed holds metadata, and the data never leaves your platform. Deployment covers a range, from fully managed to almost everything inside your perimeter.
SaaS
VaultSpeed runs the control plane, the agents and the LLM gateway as a managed single tenant service. The generated code lands on your platform.
Hybrid
Agent sessions run in ephemeral sandboxes on your infrastructure, against your LLM gateway and your approved LLMs, with spend capped at the platform level.
Inside your perimeter
Almost everything runs inside your network, for organizations where nothing may leave it. The control plane directs the work, and the work runs next to your data.
Metadata, not data
Holds metadata, not your data
VaultSpeed works from the data model, the source structures, the mappings and the lineage. The data plane stays with you: the generated code is delivered into your CI/CD process and runs on your platform without VaultSpeed in the loop. There is no runtime dependence and no licensed engine required to keep the code executing.
Bring your own LLM. The LLMs you have vetted are used as they are, with no markup on inference and no token resale, so routing and spend stay with you.
- The data model and its definitions
- Source structures, keys and mappings
- The lineage of every transformation
- The generated code, versioned in Git
- Your data, on your platform
- The runtime: the code runs without VaultSpeed
- Your LLM contract and your token spend
- Your Git, your CI/CD and your credentials
Nothing ships without review
Agents propose, people and reviewing agents approve. Every proposal is reviewed and versioned in Git before it reaches your platform, and every session runs inside limits your operators set.
Reviewed before it ships
Ephemeral sandboxes
One LLM gateway
Spend caps
Bring your own inference
A reviewer checks three things here: where prompts go, which LLMs are approved, and whose bill the tokens land on. The gateway points at one of three places, and the answer holds for all three.
Inference inside your Snowflake account
The gateway calls Cortex in the account and region you already run. Consumption lands on your Snowflake bill, under the roles and budgets you already govern.
- No data or prompt leaves the Snowflake boundary
- LLMs Snowflake has approved for your account
- Spend on the contract you already have
Inference inside your Databricks workspace
The gateway calls Model Serving endpoints in your workspace, governed by Unity Catalog. Genie works from the same semantic views the generator produces.
- Inference stays inside the workspace
- Unity Catalog permissions apply
- Spend on your Databricks commit
When you run more than one platform
When your data is not on one platform, the gateway points at Bedrock. Two ways to run it.
- Prompts and responses are never used to train models
Which LLM you use is a configuration, not an architecture decision. The context store, the skills and the review flow do not change when the inference does.
Customer story · Wealth management
We knew if we could get the hard part right first, everything else would fall into place. VaultSpeed made that possible.
Certifications and evidence
What is verifiable today
ISO/IEC 27001:2022 certified
Data residency per deployment
Single sign-on and roles
Who is accountable
Your integrator keeps delivery accountability, and the review rules define who can ship what: agents propose, your reviewers approve, and every change is tracked and reversible in Git.
Talk to us
Start with what a reviewer can check
Share this page with your security or governance team, then bring their questions to a working session with your own cloud setup as the reference.