Security and compliance

Security, compliance and sovereignty

Deployment options, the compliance matrix, model governance, data residency and what is shared in a discovery session.

Updated: September 2026

Deployment options

AI must meet the same standards as every other critical system. Aginies is built to the requirements of regulated sectors such as finance, insurance and healthcare; data stays where it must. Four deployment models deliver the same platform.

OptionWhere data livesWhere models runWhen it fits
On-premise / air-gapThe enterprise’s own data centre; no external connectionoss and speech models served insideThe most sensitive data; regulatory obligation
HybridSensitive workloads insideoss inside; outside only with masked data through a secure gatewayElastic capacity needs; a mixed scenario portfolio
Private cloud / dedicated regionA single-tenant region reserved for the enterpriseInside the region; data residency guaranteedEnterprises that want residency guarantees without running a data centre
GPU-as-a-ServiceInside national bordersElastic GPU capacity that scales with usageOn-prem model serving without capital outlay

Compliance matrix

Aginies is a SOC 2 Type II and ISO 27001 compliant platform; the control set is documented for internal audit. The matrix below summarises the compliance areas and how the platform addresses each.

AreaStatusWhat it covers
SOC 2 Type IICompliant platformThe control set is documented for internal audit
ISO 27001Compliant platformInformation security management
KVKK & GDPRCompliancePersonal data map, data residency guarantee, deletion and access requests
BDDK IT regulationCompliant deploymentFor banks, primary and secondary systems in-country; audit-ready deployment
SSO / SAML & RBACBuilt inFine-grained roles, workspace isolation, per-agent access policies
PII masking & anonymisationBuilt inMasking at ingestion, configurable redaction, anonymisation of all requests
Audit trailBuilt inInput, output, model version, rule set and user for every agent action and model call
Kill-switchBuilt inEmergency shutdown and automation limits on critical decisions; mandatory human approval
“Compliant platform” means the control set is designed and documented against the relevant standards; it is not a claim of independent certification.

Model governance

Model-agnostic, fine-tuned. Hub Aginies holds enterprise fine-tuned versions of proprietary models, open-source-based on-prem models and Turkish speech models in one catalogue. There is no vendor lock-in; switching models does not mean rewriting the agent.

  • Model proxy: cloud models reached with the enterprise’s own keys through one point
  • Keys stored encrypted; usage reported per agent, unit and channel
  • Every request to an external model is masked and anonymised
  • Fallback model strategy: operations continue through provider outages
  • Prompt versioning: which agent ran with which prompt and model version is recorded
  • On-prem oss models for sensitive scenarios; data never leaves the enterprise

Data residency and sovereignty

Sovereign design means control of data and models stays with the enterprise. In on-premise and air-gapped deployments no data leaves; in hybrid deployments only masked data goes outside, through a secure gateway. GPU-as-a-Service provides elastic capacity inside national borders.

  • Personal data map: which data, in which system, for what purpose, for how long
  • Data residency guarantee: contractual in dedicated-region and on-prem options
  • For banks, primary and secondary systems in-country
  • Deletion and access requests: recording and response aligned with KVKK and GDPR
  • Voice and code data: Voice and Code Aginies run on-prem

What is shared in a discovery session

A discovery session is a working meeting to understand the enterprise’s scenarios and constraints. The following materials are shared so that security and compliance teams get their answers early.

  • Reference architecture and a detailed schema of the deployment options
  • Documentation of the SOC 2 Type II and ISO 27001 compliant control set for internal audit
  • Data flow and masking design: which data reaches which model, in what form
  • Model catalogue and proxy setup; key management and fallback strategy
  • A sample audit report and run trace
  • The five-layer assessment scorecard for the selected scenarios
If the enterprise’s sector-specific requirements are shared before the session, the materials are prepared for those constraints.