<!-- https://widemoat.ai/security · ru: https://widmo.ru/security -->

# AI that lives in your perimeter.

> Wide Moat runs inside your infrastructure or your private cloud. Every request passes through one governed gateway, access follows your identity provider, and every prompt, cost and action is logged.

## What stays inside, and how.

- **Your data never leaves** — Sensitive paths run on your own models and infrastructure — on-prem or your private cloud.
- **One governed gateway** — Every request is routed, budgeted, rate-limited and logged. Nothing talks to a model on its own.
- **Access-aware by design** — SSO and directory groups flow into every call — people see in AI only what they already can.
- **Fully observable** — Every prompt, cost and action is measured — so adoption and risk are both visible.

## Two deployment models, the same controls.

**In your VPC** — Wide Moat runs in your cloud account. You keep control of networking, access, data and connected services.

- Your cloud perimeter
- Your access rules
- Infrastructure as code
- Control of data and connections

**Wide Moat SaaS** — A fully managed environment without running the platform infrastructure yourself. Connect approved company systems securely and start faster.

- Fast start
- Updates operated by Wide Moat
- Secure system connections
- One view of models and spend

## One identity, one policy, one audit trail.

- **Identity** — The assistant, agents and internal apps inherit the same user and source-system permissions.
- **Models and policy** — Routing, data boundaries, approvals, budgets and audit apply across the platform.
- **Human control** — Actions can require approval, and exceptions are escalated to a person with the source and reason.

## Found a vulnerability?

Write to contact@widemoat.ai

## Documentation for your questionnaire.

Architecture, data flows, deployment runbooks and the answers to your security questionnaire are available on request. We state what is in place and what is not, with no certifications claimed that we do not hold.

## Bring your security team to the first call.

We will walk through the perimeter, the gateway and the access model on your own deployment option.
