Product · Security
You keep your stack.
You keep control.
Spotonix is deployed in the customer VPC. Security review then makes four boundaries explicit: where components and artifacts live inside that environment, what the model endpoint receives, which identity executes SQL, and what evidence is retained.
The review model
Four boundaries.
Four separate answers.
Collapsing these into “in your environment” or “uses your permissions” hides the decisions a security team actually needs to make.
Customer-VPC application and storage
Spotonix is deployed in the customer VPC. Document the customer account, region, and where workspace context, logs, caches, result artifacts, backups, and support tooling operate and persist.
Model endpoint
Record the provider, model, endpoint, key owner, region, provider terms, retention settings, and context included in each request.
Warehouse identity
Identify the credential that executes SQL, then test its grants, denied paths, row restrictions, and column restrictions in the chosen environment.
Visible and retained evidence
Separate what is visible in the live answer experience from what is persisted, exportable, linked across systems, or retained for later review.
The request path
Trace one question
across every system boundary.
For each checkpoint, record the component, operator, region, credential, input, output, log, storage location, retention policy, and deletion path.
Business question
A user submits a question through the supported product or model path.
Interpretation request
The configured model path helps resolve the question against available company context.
Visible plan
The interpretation and intended analysis become inspectable before execution.
Query generation
Query logic is generated and material bindings are checked.
Warehouse execution
The configured database connection runs the query and returns the result artifacts.
Evidence to collect
Every security answer needs
an enforcement point and a test.
The result of the review should be a deployment-specific data-flow record and control matrix—not an inference from product architecture.
| Review question | Evidence | Decision owner |
|---|---|---|
| Where does each component run in the customer VPC? | Customer-VPC deployment diagram with account, operator, region, network route, and support path | Application and security teams |
| What crosses the model boundary? | Representative request payload, provider endpoint, terms, and retention configuration | AI platform and security teams |
| Which identity executes SQL? | Credential mode plus permitted and denied warehouse tests | Data platform and security teams |
| What persists and for how long? | Artifact inventory, storage location, retention schedule, backup, and deletion test | Application and data owners |
| What can another user inspect? | Cross-role access test for questions, plans, logic, sources, and stored results | Identity, application, and data owners |
Claims that stay conditional
A valid answer for one topology
is not a universal product claim.
These statements may become true for a specific deployment. The security review must earn them with the actual configuration and evidence.
“Nothing leaves the environment.”
That requires a complete data-flow inventory covering model requests, results, telemetry, logs, caches, support access, and backups for the chosen topology.
“Queries run as each user.”
That requires delegated warehouse identity and representative access-policy tests. A service credential is a different execution model.
“The provider does not train on our data.”
That depends on the selected provider contract, endpoint, account, and settings; it cannot be inferred from the Spotonix interface.
“Every action has a durable audit record.”
The live workflow exposes a plan and answer basis. Persistence, stable identity, actor linkage, export, tamper controls, and retention need separate evidence.
“The deployment is compliant.”
Compliance depends on the customer use case, topology, controls, contracts, and any relevant third-party attestations—not a marketing-page label.
Current public posture
State what is observable.
Scope everything else.
Capability labels below describe the public evidence boundary. They do not replace the deployment review.
Visible interpretation and plan
LiveThe workflow exposes the interpretation and analytical plan. Durable plan identity, actor linkage, export, tamper controls, and retention are separate evaluation requirements.
Configurable model paths
LiveAnthropic, Google Gemini, and OpenAI backends are configurable. Provider, model, endpoint, credential ownership, region, and data-usage terms remain deployment decisions.
Customer-VPC hosting
LiveThe application is deployed in the customer VPC. The customer account, region, runtime, storage, network routes, and support path are recorded for the selected topology.
Identity, retention, and deletion
EngagementAuthentication, database identity, storage locations, deletion, telemetry, support access, and backup handling are confirmed for the selected topology.
Third-party attestations
RoadmapSpotonix does not currently hold a SOC 2 attestation. Ask for the present status and scope rather than assuming a certification from adjacent controls.
Continue the evaluation
Bring the hard questions
before production.
Share the preferred topology, identity model, data classifications, model-provider requirements, retention rules, and security questionnaire during the fit check.
Integrations
Confirm the source formats, onboarding mappings, model path, and warehouse path.
Review coverage →Architecture
Inspect the component and deployment decisions behind the request path.
Review architecture →Evidence
Include retries, interventions, human verification, and failures in the proof record.
See the proof method →