Security, compliance and sovereignty
Deployment options, the compliance matrix, model governance, data residency and what is shared in a discovery session.
Updated: September 2026Deployment options
AI must meet the same standards as every other critical system. Aginies is built to the requirements of regulated sectors such as finance, insurance and healthcare; data stays where it must. Four deployment models deliver the same platform.
| Option | Where data lives | Where models run | When it fits |
|---|---|---|---|
| On-premise / air-gap | The enterprise’s own data centre; no external connection | oss and speech models served inside | The most sensitive data; regulatory obligation |
| Hybrid | Sensitive workloads inside | oss inside; outside only with masked data through a secure gateway | Elastic capacity needs; a mixed scenario portfolio |
| Private cloud / dedicated region | A single-tenant region reserved for the enterprise | Inside the region; data residency guaranteed | Enterprises that want residency guarantees without running a data centre |
| GPU-as-a-Service | Inside national borders | Elastic GPU capacity that scales with usage | On-prem model serving without capital outlay |
Compliance matrix
Aginies is a SOC 2 Type II and ISO 27001 compliant platform; the control set is documented for internal audit. The matrix below summarises the compliance areas and how the platform addresses each.
| Area | Status | What it covers |
|---|---|---|
| SOC 2 Type II | Compliant platform | The control set is documented for internal audit |
| ISO 27001 | Compliant platform | Information security management |
| KVKK & GDPR | Compliance | Personal data map, data residency guarantee, deletion and access requests |
| BDDK IT regulation | Compliant deployment | For banks, primary and secondary systems in-country; audit-ready deployment |
| SSO / SAML & RBAC | Built in | Fine-grained roles, workspace isolation, per-agent access policies |
| PII masking & anonymisation | Built in | Masking at ingestion, configurable redaction, anonymisation of all requests |
| Audit trail | Built in | Input, output, model version, rule set and user for every agent action and model call |
| Kill-switch | Built in | Emergency shutdown and automation limits on critical decisions; mandatory human approval |
Model governance
Model-agnostic, fine-tuned. Hub Aginies holds enterprise fine-tuned versions of proprietary models, open-source-based on-prem models and Turkish speech models in one catalogue. There is no vendor lock-in; switching models does not mean rewriting the agent.
- Model proxy: cloud models reached with the enterprise’s own keys through one point
- Keys stored encrypted; usage reported per agent, unit and channel
- Every request to an external model is masked and anonymised
- Fallback model strategy: operations continue through provider outages
- Prompt versioning: which agent ran with which prompt and model version is recorded
- On-prem oss models for sensitive scenarios; data never leaves the enterprise
Data residency and sovereignty
Sovereign design means control of data and models stays with the enterprise. In on-premise and air-gapped deployments no data leaves; in hybrid deployments only masked data goes outside, through a secure gateway. GPU-as-a-Service provides elastic capacity inside national borders.
- Personal data map: which data, in which system, for what purpose, for how long
- Data residency guarantee: contractual in dedicated-region and on-prem options
- For banks, primary and secondary systems in-country
- Deletion and access requests: recording and response aligned with KVKK and GDPR
- Voice and code data: Voice and Code Aginies run on-prem
What is shared in a discovery session
A discovery session is a working meeting to understand the enterprise’s scenarios and constraints. The following materials are shared so that security and compliance teams get their answers early.
- Reference architecture and a detailed schema of the deployment options
- Documentation of the SOC 2 Type II and ISO 27001 compliant control set for internal audit
- Data flow and masking design: which data reaches which model, in what form
- Model catalogue and proxy setup; key management and fallback strategy
- A sample audit report and run trace
- The five-layer assessment scorecard for the selected scenarios