Your data never leaves
Sensitive paths run on your own models and infrastructure — on-prem or your private cloud.
Security
Wide Moat runs inside your infrastructure or your private cloud. Every request passes through one governed gateway, access follows your identity provider, and every prompt, cost and action is logged.
Data boundaries
Sensitive paths run on your own models and infrastructure — on-prem or your private cloud.
Every request is routed, budgeted, rate-limited and logged. Nothing talks to a model on its own.
SSO and directory groups flow into every call — people see in AI only what they already can.
Every prompt, cost and action is measured — so adoption and risk are both visible.
Two deployment models
Governance
The assistant, agents and internal apps inherit the same user and source-system permissions.
Routing, data boundaries, approvals, budgets and audit apply across the platform.
Actions can require approval, and exceptions are escalated to a person with the source and reason.
Responsible disclosure
Write to contact@widemoat.ai. Our disclosure contact is also published in security.txt (RFC 9116).
Security review
Architecture, data flows, deployment runbooks and the answers to your security questionnaire are available on request. We state what is in place and what is not, with no certifications claimed that we do not hold.
Start with one valuable function
We will walk through the perimeter, the gateway and the access model on your own deployment option.