Security

AI that lives in your perimeter.

Wide Moat runs inside your infrastructure or your private cloud. Every request passes through one governed gateway, access follows your identity provider, and every prompt, cost and action is logged.

See deployment options

Data boundaries

What stays inside, and how.

Your data never leaves

Sensitive paths run on your own models and infrastructure — on-prem or your private cloud.

One governed gateway

Every request is routed, budgeted, rate-limited and logged. Nothing talks to a model on its own.

Access-aware by design

SSO and directory groups flow into every call — people see in AI only what they already can.

Fully observable

Every prompt, cost and action is measured — so adoption and risk are both visible.

Two deployment models

Two deployment models, the same controls.

VPC

In your VPC

Wide Moat runs in your cloud account. You keep control of networking, access, data and connected services.

  • Your cloud perimeter
  • Your access rules
  • Infrastructure as code
  • Control of data and connections
SaaS

Wide Moat SaaS

A fully managed environment without running the platform infrastructure yourself. Connect approved company systems securely and start faster.

  • Fast start
  • Updates operated by Wide Moat
  • Secure system connections
  • One view of models and spend

Governance

One identity, one policy, one audit trail.

Identity

The assistant, agents and internal apps inherit the same user and source-system permissions.

Models and policy

Routing, data boundaries, approvals, budgets and audit apply across the platform.

Human control

Actions can require approval, and exceptions are escalated to a person with the source and reason.

Responsible disclosure

Found a vulnerability?

Write to contact@widemoat.ai. Our disclosure contact is also published in security.txt (RFC 9116).

Security review

Documentation for your questionnaire.

Architecture, data flows, deployment runbooks and the answers to your security questionnaire are available on request. We state what is in place and what is not, with no certifications claimed that we do not hold.

Start with one valuable function

Bring your security team to the first call.

We will walk through the perimeter, the gateway and the access model on your own deployment option.