Dispatches
Trust · Palladium deployment

Palladium: deploy the full platform inside your environment

Managed cloud, your VPC, on-prem, air-gapped, or GovCloud—same product everywhere, with data residency per workspace and zero egress if you want it.

A global professional services firm has run Athena air-gapped in its own tenant for over a year with thousands of users across multiple countries and regions.

Frontier models (ZDR)Support (JIT only)YOUR AZURE TENANT · VPC / ON-PREM / AIR-GAPPED / GOVCLOUDAthena runtimeStudios · Sheets ·Computers ·LakehousePermission service· fail-closedModel gateway ·BYO keysModel API calls cross only when using frontier providers with ZDR
Fig. 01Every Athena component runs inside your boundary with optional zero egress
  • SOC 2 Type II
  • HIPAA
  • Zero data retention with every model provider
  • No training on your data
  • A dozen-plus enterprise security reviews passed
  • Managed-cloud parity everywhere
The problem

Sprawl is the problem. In-environment is the answer.

Many AI tools run only in the vendor's cloud, which makes the security review hard, and they often stop at a chat window. Building in-house takes forever and has to be rebuilt every time the stack changes. So regulated organizations often end up with a narrow tool that could get approved, and a dozen point solutions around it.

Sprawl is the problem. In-environment is the answer.

Vendor sprawlOne platform6 managed cloud only4 pending review2 approved, limited12 AI vendors totalLeast capable tool that could passAthenaDeployed in our tenantApproved · full platformIn-environment, frontier AI, feature parity
Fig. 02In-environment deployment eliminates the vendor-risk spreadsheet
How it works

Pick the boundary. We fit inside it.

  1. Choose the deployment. Managed cloud for speed. Your VPC on GCP, Azure, or AWS for control. On-prem, air-gapped, or GovCloud where policy requires. Feature parity across all of them.

  2. Set residency. Region-bound storage per workspace. EU data stays in the EU. US data stays in the US.

  3. Choose the models. 60+ models with zero-data-retention agreements; bring your own keys; or run open-source models inside the boundary so no call leaves.

  4. Keep the permissions you have. Source-system permissions inherited per user in real time. Files stay where they live; the cache is TTL-only. If the permission service cannot be reached, the action does not run.

01YourenvironmentVPC / on-prem /air-gapped / …02AthenaruntimeStudios ·Sheets03PermissionserviceInherits fromsource systemsa person approves04ModelgatewayBYO keys05Frontiermodel …60+ models withZDR · optionalSupport access: JIT, time-bounded, double-logged, approved by you
Fig. 03Pick the boundary, set residency, choose models—permissions stay fail-closed
In practice

Deployment in practice

A global professional services firm, air-gapped, over a year.

The audit suite runs inside the firm's own cloud tenant: zero egress, red-team-hardened roles, a restrictive computer mode, multi-region data residency. Over 1,000 users across multiple countries and regions. Production for over a year.

Support (JITGLOBAL PROFESSIONAL SERVICES FIRM · OWN CLOUD TENANT · AIR-GAPPEDAthena runtime ·thousands of usersData residency:Region AData residency: EMEAData residency: AmericasZero egress ·red-team-hardenedrolesProduction forover a yearFive localities, restrictive computer mode
Fig. 04A global professional services firm runs air-gapped with multi-region residency and thousands of users

A Fortune 50 retailer that wanted to own its AI stack.

The retailer required deployment inside its own environment, and Athena passed those requirements.

Fortune 50 retailer evaluationTrigger · Vendors who could deploy in our VPCDeploys in our VPCFeature parity in-environmentFail-closed permissionsData residency per workspaceFull platform (not chat only)Two vendors could. Athenawas one of them.Own your AI stack evaluation
Fig. 05The evaluation came down to in-environment deployment—two vendors qualified

Just-in-time, audited support access.

No standing vendor credentials. Access is requested per incident, approved by you, time-bounded, and logged twice: by the platform and by your cluster.

Athena wants toAccess your cluster for incident #4412Athena engineer requests 2h accessReason: incident #4412Expires: 16:40WAITING FOR A PERSONTime-bounded, logged twiceJIT audited support access · no standing credentials
Fig. 06Support access is requested per incident, approved by you, and double-logged

Hard delete and retention on your schedule.

End-of-engagement purge. Discovery-aware retention controls. Usage export. Twice-yearly hard delete is a configured policy at one professional-services customer.

Retention Policy · Engagement AssetsArchived6-month cycleNext hard deleteMar 15Policy interval6 monthsQ1Q2Q3Q4Q1Twice-yearly purge configured
Fig. 07A professional-services customer hard deletes engagement assets every six months

Self-hosted Office, self-hosted BI, self-hosted everything.

Studios, Sheets, the Lakehouse, Computers, and the model gateway all run inside the boundary. An Office suite and a BI layer that never touch Microsoft.

MicrosoftExternal BICloud OfficeYOUR BOUNDARY · VPC OR ON-PREMStudiosSheetsLakehouseComputersModel gatewayFull platformruntimeOffice suite and BI layer that never touch Microsoft
Fig. 08Studios, Sheets, the Lakehouse, Computers, and the model gateway all run in-boundary
What customers say
“The performance, say, the kind of speed and latency on those APIs for creating assets, was better in [our private cloud] than it was in managed cloud.”
Audit lead · A global professional services firm
“It's good to understand the capability of the platform. That how far, and how quickly you guys can get these things going [...] that has been impressive overall.”
VP-level AI leader · A Fortune 500 retailer
“Lets us get a lot more out of our data than [...] We can sit on top of all of the data in [our data warehouse] as opposed to just, like, our little ingested, you know, three gigabytes semantic models. I think we have a lot of power here.”
Analytics lead · A Fortune 500 retailer
“Gave Athena the spreadsheet, explained which column I was trying to figure out, and then ten secs it told me... exactly how the calculation was based on the other data.”
Analyst · A global manufacturer
“He wrote the entire stuff. By itself. And I was there, and I was thinking, alright. If I had to write all this stuff, I mean, I would've spent days, days, days.”
Manufacturing analyst · A global manufacturer
“I send that to the programmer and he said, alright. I read your file. I copied the section of the code because he has the right interface, and it works. Wow. Just like magic.”
Manufacturing analyst · A global manufacturer
“One workspace. All different, let's say, avatars of their output data. Right? Suddenly, it's dashboard. Excel is here. PowerPoint is when it's all together. It's very impressive.”
Global Sustainability lead · A global manufacturer
“Use the Athena platform probably closer to the concept and how it was designed, like, with the spaces architecture where you've got a set of primitives and capabilities, and you bring together the right set of capabilities to solve a task.”
Audit lead · A global professional services firm
“Digital worker, it gets spun up, it gets given access to the toolkits that it needs. It gets given access to the data that it needs. Just exists for the period it needs to exist to perform the task. And then it gets torn back down again afterwards.”
Audit lead · A global professional services firm
“I like that direction, that concept of the agent is the agent. It becomes an entity in its own right with its own ownership and its own missioning, and you get rid of the gray area and the blurry lines.”
Audit lead · A global professional services firm

Verbatim from customer calls. Customers anonymized.

Posture

Our posture

Our posture is not "don't put your data on us." It is that we are partnered with you: the platform runs where you say, with your permissions, and what you build is yours. Worse comes to worst, you walk away with the stack.

Governance

Governance, stated plainly

  • Deployment options with feature parity: managed cloud, VPC (GCP, Azure, AWS), on-prem, air-gapped, GovCloud.

  • Data residency per workspace. Zero-egress observability available.

  • 60+ models, zero data retention with every provider, no training on your data, BYO keys, in-boundary open-source models.

  • Fail-closed permissions. JIT audited support access. Hard delete on your schedule.

What to plan for

Air-gapped means updates ship on your change window, not ours. You will trail managed cloud by however long your change window is.

FAQ

Where can Athena run?

Our cloud, your cloud, on-premises, or air-gapped, with the same platform everywhere.

Does our data leave our environment?

Not when you deploy in your own environment.

How is vendor access controlled?

There is no standing access. Every request is approved by you, time-bounded, and logged.

The rest of the platform

Related products and stories

Send the security questionnaire.

We will answer it, then show you the platform running inside a boundary like yours.