Your infrastructure, your keys, your data
Run the whole control plane in your own cloud with your own model keys. When agents run under BYOC, their prompts, tool inputs, and outputs never have to leave your infrastructure — and when they do run on our managed cloud, this page tells you exactly what we store. No hand-waving, no certification we don't hold.
Built so your data can stay yours
The same product runs two ways — on our managed cloud, or self-hosted in your own account. Both keep your model keys encrypted and your audit trail complete; self-hosting adds the guarantee that agent payloads never leave your environment.
Bring your own cloud (BYOC)
RunAIAgents ships as a single-server deployment — the app, a local Redis, and a reverse proxy — that runs in your own server or cloud account. Your agents' inputs and outputs stay in your infrastructure; we hold only run metadata (duration, cost, status), never payload content.
Bring your own keys (BYOK)
Connect your own OpenAI and Anthropic keys. They're encrypted with AES-256-GCM through one audited module and used only at runtime — we never proxy, log, or retain your provider tokens. In a self-hosted deployment they never leave your environment.
One audited encryption module
Every stored credential passes through a single AES-256-GCM module — no inline or ad-hoc crypto anywhere else. Encrypted keys, credential blobs, and tokens are never serialized back to any client, by schema contract.
Data residency you choose
A BYOC deployment runs in the region and account you pick, including GCC (UAE, Saudi). Regulated and sovereign deployments are a first-class case, not an afterthought.
Where your data lives, per deployment
A managed, multi-tenant platform processes your prompts and outputs on the vendor’s infrastructure — that is what “managed” means. With BYOC, RunAIAgents runs inside your own cloud account, so those payloads never leave it in the first place.
| Data | Managed cloud | Self-hosted (BYOC) |
|---|---|---|
| Model & OAuth credentials (BYOK) | Encrypted at rest (AES-256-GCM), used only at runtime, never proxied or logged. | Held and used inside your own deployment — they never reach us at all. |
| Agent inputs & outputs (prompts, tool payloads) | Processed on our infrastructure to run the agent and stream results back to you. | Stay inside your cloud account. We store only run metadata, never payload content. |
| Run metadata (duration, cost, status) | Stored so you get history, analytics, and billing. | Reported back for the same history and billing — no prompt or output text. |
| Security audit log | Immutable, org-scoped, owner-gated; exportable as CSV or streamed to your SIEM. | Same immutable trail, same CSV / SIEM export — from your own deployment. |
Stated plainly, not rounded up
SOC 2 Type II — in progress, not yet certified
We are actively building our SOC 2 program around controls that are already live in the product — encryption, access control, monitoring, audit logging. We do not claim certification until an auditor has issued a report.
GDPR & Data Processing Addendum
A DPA is available to execute as part of your agreement, and every subprocessor that touches customer data is listed with its purpose and data scope. Self-hosting shrinks that list to the infrastructure you already run.
The full control-by-control breakdown, mapped to the Trust Service Criteria, lives on the Trust Center.
Want it running in your own cloud?
Tell us about your environment and compliance requirements and we’ll walk you through a BYOC deployment, BYOK setup, and the data boundaries above — with data-flow documentation available under NDA.