DEMO ENVIRONMENT · sample data for “Northwind Global” · restart tour
Dana Whitfield

Deployment & data residency

Where your data lives — and how it runs

For Northwind Global, AIDE is deployed as a sealed Docker container inside the company’s own Microsoft Azure tenant — the data stays put; only an approved aggregate ever moves. The same sealed application can run in AWS, Oracle Cloud, or Google Cloud private tenants instead — pick the cloud you already trust.

Northwind Global — Microsoft Azure tenantWest Europe (Netherlands)Everything inside this boundary stays in Northwind’s cloud account.
Connected sources
Slack · Google · GitHub · HubSpot · AI-vendor telemetry — read in-boundary
Sealed AIDE container
Azure Kubernetes Service — sealed container
In-tenant AI scoring
Azure OpenAI — in-tenant endpoint
Private storage
Azure Blob Storage (private) · Azure Database for PostgreSQL · per-tenant git repo

→ Raw content & individual data never leave. Only a founder-approved, anonymized aggregate is transmitted for benchmarking.

Microsoft Azure — deployment stack

Active for Northwind Global
Compute (sealed container)
Azure Kubernetes Service — sealed container
AI model endpoint (in-tenant)
Azure OpenAI — in-tenant endpoint
Object storage (private bucket)
Azure Blob Storage (private)
Database
Azure Database for PostgreSQL
Secrets / key management
Azure Key Vault (KMS)
Identity & access
Microsoft Entra ID

Same sealed application, same guarantees — deployed into whichever cloud Northwind already trusts. Switching providers changes only the managed-service names above.

How it runs

Four steps, all inside your boundary

1

Deploy a sealed container in your tenant

AIDE runs as a sealed Docker application inside Northwind Global’s own Microsoft Azure tenant (AKS) — not our infrastructure. You hold the cloud account; we hold no copy of your data.

2

Read only shared-access content, in-boundary

It reads content the team already shares — department channels, group drives, wikis — plus AI-vendor usage telemetry. No inboxes, no one-to-one messages.

3

Build the graph & score on in-tenant models

The knowledge graph, RAG and AI scoring all run on model endpoints inside your boundary (Azure OpenAI / Bedrock / Vertex / OCI GenAI) — nothing is sent to any outside AI provider.

4

Two outputs, both in your control

Your full internal report stays in-tenant. A standardized, anonymized aggregate is produced for benchmarking — and your team approves it before anything is ever shared. Nothing auto-transmits.

The guarantees

The measurement is lower-risk than the status quo

EncryptedIn transit (TLS) and at rest (cloud-native KMS)
In your tenantRuns in Northwind’s own Azure account, not ours
Tenant-isolatedPer-tenant database, bucket prefix & git repo
Founder-approved egressOnly an anonymized aggregate leaves — after review
Audit-loggedEvery access to tenant data is recorded
Governance-readyDPIA + works-council support before any content is read

Read the full data-governance model in the CIO briefing. Next in the tour → Dashboard.