Know where the data goes.
Know who can reach it.
Local inference removes the need to send prompts to an external model API. A defensible deployment also has to account for retrieved files, tool output, traces, updates, and support access. We scope those paths with your engineering and security owners.
CUSTOMER CONCERNCUECLOUD DEPLOYMENT APPROACHWHAT TO VALIDATE TOGETHER
Where does our technical data go?
Run selected models on Vault and host the Blitz workflow internally. Include prompts, generated code, tool results, and telemetry in the data-flow review.
Approved destinations, outbound connections, storage locations, backup handling, and retention.
Can another program see our material?
Scope repository connections, working context, and tool credentials by program. Agree whether separate deployments are required for the customer’s boundary.
Identity mapping, denied-access tests, cross-program retrieval behavior, and trace visibility.
Can the agent change a delivered system?
Start with offline engineering work and reviewable diffs. Configure permitted commands and keep release authority with your existing engineering process.
Write permissions, test environments, review gates, and separation from live equipment and release credentials.
Can we account for what happened?
Host agent traces and operational telemetry internally, with collection and access scoped to your requirements. Treat logs containing technical data as part of the protected workflow.
Recorded events, access to logs, retention, investigation procedures, and evidence your team needs to retain.
How is the installation maintained?
Plan model and software delivery, update approval, rollback, and support before installation. Scope an offline process where the environment requires it.
Artifact provenance, approved versions, package transfer, support access, and the responsible owner for each control.