Enterprise Deployment

Your Infrastructure. Your Rules. Full Compliance.

Deploy Sage entirely within your own cloud, bring your own AI provider keys, and lock every byte of customer data to the region you choose. Zero vendor lock-in, full audit trail.

Bring Your Own Cloud (BYOC)

Deploy Sage entirely within your own cloud account. Your VPC, your security perimeter, your billing.

Cloud ProviderSupported ServicesStatus
AWSDynamoDB, S3, Lambda, SQS, CloudFrontFully validated
Google CloudCloud Spanner, GCS, Cloud Run, Pub/SubFully validated
Microsoft AzureCosmos DB, Blob Storage, Azure Functions, Service BusFully validated
Any cloudTerraform modules are provider-agnostic for compute and queue layersPortable
On-premiseAir-gapped and sovereign cloud deploymentsSupported

Bring Your Own Keys (BYOK)

You are never forced to route AI model requests through Advent AI's accounts. Use your own API keys from any provider and the latest available models from each.

OpenAI

Direct to your OpenAI billing, including GPT-series and reasoning models

Anthropic

Direct to your Anthropic account, including Claude-series models

Google

Direct to Google AI billing, including Gemini-series models

Azure OpenAI

Custom endpoint and deployment ID for Azure enterprise agreements

OpenRouter

Single key routing across a wide selection of providers and models

Any OpenAI-compatible endpoint

Fine-tuned models, locally hosted models, and private deployments

Your API keys are stored encrypted in your own deployment, never transmitted to Advent AI, and are scoped per-tenant. You control spend, rate limits, and model availability directly from your provider dashboard.

Data Residency and Regional Compliance

Choose exactly where every byte of your customer data lives. No data crosses regional boundaries unless you explicitly configure multi-region replication.

RegionComplianceCoverage
EU (eu-west-1, eu-central-1)GDPREU-resident data never leaves EU infrastructure
US (us-east-1, us-west-2)CCPAUS federal and state requirements
APAC (ap-southeast-1, ap-northeast-1)Local residencyRegional data residency requirements
India (ap-south-1)DPDP ActDigital Personal Data Protection Act compliance
Sovereign / air-gappedCustomFully isolated deployments for regulated industries

Full Deployment Matrix

All modes are provisioned via the same Terraform codebase. Switching from Sage Cloud to BYOC is a configuration change, not a migration.

ModeBest ForData LocationLLM Keys
Sage Cloud (Managed)Starter and GrowthAdvent AI infrastructureSage-managed
BYOC — Single RegionMid-marketYour cloud account, chosen regionYour keys
BYOC — Multi-RegionGlobal enterpriseMultiple regions, data-residency lockedYour keys
Full Self-HostedRegulated / sovereignOn-premise or private cloudYour keys
HybridCustom requirementsConfig on Sage Cloud, data self-hostedYour keys

Security at Every Layer

Sage Enterprise ships with SOC 2 Type II compliance coverage, Role-Based Access Controls, and an independent audit trail for all data access events.

Shadow-routing provides a parallel audit path that logs every input and output for compliance review without impacting production latency.

Security Controls

  • AES-256 encryption at rest for all data layers
  • TLS 1.3 in transit on all API and widget connections
  • Per-tenant logical isolation on every database record
  • SHA-256 hashed API keys — raw keys never stored
  • Encrypted credential storage for all tool secrets
  • PII masking applied automatically at the logging layer
  • Full Terraform IaC for reproducible, auditable deployments

Frequently Asked Questions

Can I use my own AI API keys?

Yes. BYOK (Bring Your Own Keys) is supported for all major AI providers including OpenAI, Anthropic, Google, Azure OpenAI, and any OpenAI-compatible endpoint. Your keys are stored encrypted in your own deployment and never transmitted to Advent AI.

Is my data stored in my own cloud?

Yes, with BYOC (Bring Your Own Cloud). The entire Sage infrastructure stack is provisioned into your AWS, Google Cloud, or Azure account via Terraform. Advent AI provides the application layer but never touches your production data.

How does Sage handle GDPR compliance?

Sage supports region-locked deployments where EU-resident data never leaves EU infrastructure. The Memory Admin API includes right-to-erasure endpoints, and all data is encrypted per-tenant with full audit trails.

Can I switch from Sage Cloud to self-hosted later?

Yes. All deployment modes are provisioned via the same Terraform codebase. Switching from Sage Cloud to BYOC is a configuration change, not a migration project.

Ready to upgrade from chatbots to AI Agents?

Book a personalized demo to see Sage in action, or join our waitlist for early enterprise access.

or