org.tech / Governance / Posture tiers Chosen, not sold. Baseline · Standard · Strict

A posture is how hardened your deployment is. It is not a product edition, and nothing is withheld to sell you the next one.

How hardened, chosen on purpose.

Three named postures, additive, each a set of controls rather than a set of features. The same product is deployed at all three. What changes is the network path, the key custody, the audit trail, the identity requirements and where inference may run. This page gives you the whole matrix, what each posture adds to your cloud bill, and who belongs on which.

A posture, not a package.

POSTURE · 01

The word "tier" is overloaded in this industry, so be clear what it means here. A posture is a security configuration: which controls are switched on in the infrastructure that gets deployed into your account. It is not a commercial edition. There is no feature held back at Baseline to make Standard attractive, and the governance controls that matter most, the four denies on every inference call, are identical at all three.

On at every posture
Added higher up
Override, with a written reason
What it decides

The hardening of your deployment.

  • Whether the model service is reached over a private network endpoint
  • Whether an account-level audit trail is on, and for how long
  • Who holds the encryption keys
  • Whether MFA is enforced, and whether we hold any cross-account access at all
  • Whether inference is pinned to your jurisdiction
Security postureDeploy-time
What it does not decide

What the platform can do.

  • Chat, knowledge base, administration, modules and metering are the same at all three
  • The mandatory content policy and the other three denies are the same at all three
  • Per-person quotas, the invocation log and the audit of administrator reads are the same
  • Pricing is the ladder on pricing; a posture changes your cloud bill, not our fee
Product capabilityUnchanged

Every control, at every posture.

THE MATRIX

Rows are controls, columns are the three postures. Read the Baseline column carefully: it is the column most vendor comparison tables would quietly leave out.

ControlBaselineStandardStrict
Single-account isolation: one organization, one account you ownYesYesYes
Encryption in transit and at restYesYesYes
Encryption keysProvider-ownedProvider-managedCustomer-managed, rotation on
Content policy mandatory on every inference, enforced as a denyYesYesYes
Governed route, endpoint region and retention deniesYesYesYes
Least-privilege identity policy, everything as codeYesYesYes
Model invocation logging: model, caller, latency, tokens. No prompt or answer textYesYesYes
Private network endpoint to the model serviceNoYesYes
Network-attached chat computeNoYesYes
Account-level audit logging: multi-region, file validation, one-year retentionNoYesYes
MFA enforcedNo, can be addedYesYes
Our management access into your accountNone existsScoped, session-cappedScoped, session-capped
Inference residencyGlobal routingGlobal routingPinned to your jurisdiction
Storage regionChosen per deploymentChosen per deploymentChosen per deployment

Two rows are judgments rather than measurements. "None exists" at Baseline means no cross-account role for us is created at all, which is stricter than the columns to its right and slower when you want help. And the residency row costs capability rather than money: see data residency for the model list a pin leaves you.

Baseline, said plainly

Baseline has no private networking and no account-level audit trail. Traffic to the model service is signed and encrypted from inside the cloud, which is a defensible position, but it is not private networking and we will not call it that. A formal security review will usually want Standard.

Pick the one that matches your obligation.

WHO BELONGS WHERE

In plain words, without the euphemisms. The right posture is usually obvious once someone says out loud what the deployment will actually hold.

01 Baseline

A first evaluation.

Low-sensitivity material, an internal pilot, a team finding out whether governed AI is worth the effort. Cheap to run and genuinely governed on the controls that matter most. Not the posture to put a regulated corpus on, and not the posture to take into a customer's vendor review. If you are here to prove value first, start here and move up.

Evaluation, low sensitivityLowest cloud cost
02 Standard

An active compliance program.

You have customer security reviews, an internal control framework, or an auditor who will ask for an audit trail and key management. This is the posture we recommend by default, and the one we would bring to a reviewer. Private network endpoint, account audit trail with a year of retention, managed keys, MFA enforced, and our access scoped and session-capped.

Reviews and auditsRecommended default
03 Strict

A hard residency requirement.

A jurisdictional obligation you cannot meet with disclosure, or a formal evidence pack that requires customer-managed keys with rotation. Everything Standard has, plus key custody and the inference pin. Go in knowing the pin's price in models, decide per workload, and read data residency before committing.

Residency and key custodyCapability cost

The posture shows up on your cloud bill.

WHAT IT COSTS YOU

Not on our invoice. Our fees are the ladder on pricing and they do not change with posture. What changes is the infrastructure running in your own account, billed to you by your provider at list price. These are figures we have seen, not a quote.

$5-10/mo
Baseline · platform infrastructure
$110/mo
Private-network postures · infrastructure
$40-120/mo
Light team usage · all in
0% markup
Compute · billed to you directly

Infrastructure figures exclude inference. The all-in range is one deployment with light usage, in Canadian dollars, and yours will differ with how much people use it. Inference is the variable part: a knowledge question of roughly 10,000 tokens in and 1,000 out costs an estimated 4 to 5 cents at a mid-tier frontier model's list price. Worked through on compute costs.

The shape of the decision

Moving from Baseline to Standard costs on the order of a hundred dollars a month on your cloud bill. If a hundred dollars a month is what stands between you and a security review that passes, take the hundred dollars.

Asked, recorded, then built.

HOW IT IS CHOSEN
Discovery, before any build

A questionnaire, not a sales conversation.

The posture is chosen during discovery by walking the security posture questionnaire, which we publish so that you see the questions before the call rather than after the contract.

  • 01
    It asks, it does not assume. Your current AI landscape, residency with the tradeoff stated in models, the controls you need, your operational requirements and your compliance program. It also asks you to confirm in writing that you understand we hold no third-party attestation.
  • 02
    It outputs a recommendation. A posture, plus every place you chose to differ from it. Read it before you book.
  • 03
    Overrides carry a written reason. Any control can be moved independently, up or down. A downgrade is not refused, it is recorded: the reason goes in the posture object and the control appears as a standing exception on your in-product plan page, where your own reviewer can read it.
  • 04
    Moving up later is a release. A posture is a deploy-time parameter, so changing it is a change to the object and a deploy from a pinned release, not a rebuild of your environment and not a migration of your data.
One typed objectGOV-04b
  • DrivesThe infrastructureResolved from the posture name plus your per-control overrides
  • DrivesYour in-product plan pageThe resolved controls and the standing exceptions, rendered to the signed-in client
  • DrivesThe machine-readable exportFor your own compliance tooling
  • Cannot divergeA test fails the build if the page and the exceptions table disagree
  • Changed byA release, from a pinned tag and a clean checkout
Configuration is the policy·Same object, three readers

The three postures are deliberately coarse. Per-control overrides exist and each carries a written reason, and the combinations exercised end to end are the three named ones, so if you need an unusual mix, say so in discovery and we will tell you what it has been tested against.

Posture questions, answered.

QUESTIONS · REVIEWERS ASK
01Is Baseline safe enough for real work?

For low-sensitivity material and a first evaluation, yes: account isolation, encryption in transit and at rest, the mandatory content policy and the other three denies, least-privilege identity policy and everything as code. For a formal security review, usually not, because there is no private network path and no account-level audit trail. Baseline suits low-sensitivity use and a first evaluation, and that is how we sell it.

02Can we take the audit trail without the private network?

Technically yes, as a per-control override with a written reason, and it will show on your plan page as a non-standard configuration. Ask for it in discovery and we will test that combination on your deployment before you depend on it.

03Who can change our posture once we are live?

Nobody inside the running system. Administrators manage users, roles, grants, quotas and module channels; they cannot change the posture, residency, the model allowlist, the content policy or admit a module. Those are deploy-time parameters, changed through a release with your agreement. See administration.

04Does a higher posture change what our people can do?

Only at Strict, and only through residency: the pin limits which models can serve a request, which is a real change to what the chat can do. Baseline and Standard run the same catalogue. Everything else a posture changes is beneath the application: network path, keys, audit trail, MFA and our access.

05How does this relate to your pricing tiers?

It does not. There are no product tiers. The commercial ladder is one assessment, one deployment engagement, one monthly managed-operations fee and compute billed directly to you, and it is identical at all three postures. The word tier on this page means security posture only.

06What if our reviewer wants a control none of the three include?

Ask in discovery. Some things exist and are switched on where a deployment needs them, such as evidentiary storage with object lock, a seven-year default retention and break-glass access requiring MFA. Some things do not exist, and on those we will say no rather than write a roadmap item into a contract. The list of what we do not claim is published.

⎯⎯ Book the strategic assessment ⎯⎯

Your private AI, inside your control ·

Bring the control framework you are held to, and we will tell you which posture meets it and what that costs on your own cloud bill.