EU AI Act Annex III: 2 December 2027. See what it requires →

Your data. Your perimeter.

Choose hosted, customer-controlled, or customer-VPC deployment.

Hosted

Live in minutes

Obsvr Cloud runs ingest, PII scanning, countersigning, and the Merkle ledger with per-customer isolation.

  • Zero infra - wrap your SDK and events land immediately
  • Isolated, per-customer storage by default
  • Fastest path to a working audit trail

Bring-your-own storage

Your S3, your keys

Audit records write to an S3 bucket in your AWS account through a customer-controlled cross-account IAM role.

  • Cross-account IAM role - obsvr assumes it with short-lived creds
  • Records land as date-partitioned JSON, Athena-ready
  • Dashboard generates the bucket policies for copy-paste

In-VPC data plane

Helm or Compose

Run ingest, PII scanning, countersigning, the Merkle ledger, and evidence-pack generation inside your AWS account using the shipped customer-VPC deployment.

  • Raw prompts, responses, canonical records, and PII scan results stay in your VPC
  • You hold the countersigning key and the Merkle anchor repo
  • Deploys to your AWS account with your existing tooling

Air-gapped on-prem

Enterprise

A fully self-hosted deployment removes the hosted control-plane connection and requires a self-hosted policy/key store and dashboard.

  • No hosted control-plane connection
  • Audit trail verifies without trusting external infrastructure
  • Built for the strictest data-residency and procurement reviews

In-VPC mode: what leaves your network

The enforcement and audit pipeline runs entirely in your VPC. Only the proof syncs to the control plane - never the content it proves.

Syncs outContent hashes (HMAC-SHA-256)
Syncs outSignatures & Merkle roots
Syncs outEnforcement verdicts
Stays in VPCRaw prompts & responses
Stays in VPCPII / customer data
Stays in VPCContract or document text

You hold the countersigning key and the Merkle anchor repo - the audit trail verifies without trusting obsvr's infrastructure.