Skip to content
AI Hub Hire an agent
Data & limits

Where the data sits and what actually crosses the boundary

The parts of this you can verify from outside, we state precisely. The parts you cannot, we name as such.

Region of your choice

The hub runs on AWS. By default in the European region (Frankfurt); on request in any AWS region you name — or inside your own AWS account. Memory, archive and logs stay in the chosen region. Retention is a property of the data class, not a decision made at the moment of writing.

One flow leaves, and we name it

The request to the model carries the question and the relevant part of the memory. That is a condition of an agent working at all, not a route we picked. Everything else stays inside.

Commands run isolated

Anything the agent executes runs in a sandbox with a read-only root and writes confined to its own working directory. Verified by measurement from inside, not asserted.

Secrets are not on disk

Keys are taken into process memory at start and never written to the filesystem the agent can read.

Separate per tenant

One customer's data never mixes with another's. There is no shared pool of memory and no cross-tenant retrieval.

Your subscription, your bill

The model subscription is issued in your name. We do not resell inference, and we cannot see your usage.

What rests on discipline rather than a lock

Where a safeguard is built into a tool, it holds whether the agent cooperates or not. Where it is not, the limit rests on a written rule and the agent's discipline. From outside those two look identical, so we say which is which — and we keep moving items from the second list into the first.