NOVANEON Start a conversation

In practice · 09 of 09

Our source code does not leave our network. That is not negotiable.

For some organisations the first question is not what the work is worth, but whether they are permitted to do it at all.

This is a gate, not a feature comparison

In defence, government, central banking and market infrastructure, data egress is the entry condition. A capability that requires source code to leave the network is not a weaker option in those environments. It is not an option, and no amount of commercial flexibility changes that, because the person saying no is not buying and is not negotiating.

Treating it as a feature comparison wastes several months of everybody's time. It is better established in the first conversation than in a security review three months later, which is why it is stated here rather than in an appendix.

What in-tenant actually means

Why the security review usually stalls. The blocking question is almost never whether analysis is useful. It is where the data goes, who can see the output, and whether that can be evidenced afterwards. An architecture that answers those three before they are asked converts a three-month review into a short one.

Access control is the harder half

Egress is the question that gets asked first. Access is the one that stops deployments. A capability that describes an estate is, by construction, a capability that shows people things, and in a regulated institution not everyone is entitled to see everything. Role-based access, tenancy separation, data segregation and an audit trail of what was seen and who authorised it are what separate something that can actually be deployed from something that works in a demonstration.

This is worth knowing whether or not you ever engage us, because it is the most common reason internally built tools of this kind never reach the people they were built for.

Common questions

Can this run fully air-gapped?

Yes, where that is the requirement. It runs inside your own tenant or on your own premises, with your own model if you prefer one, and nothing crosses the boundary.

Do you require a specific cloud provider or model vendor?

No. There is no requirement to adopt a particular cloud or a particular model as a condition of the work, which is a deliberate difference from tooling that is designed to move you onto its own platform.

What is the honest limit?

It is strongest on codebases it can read. It is weaker on closed commercial software where only configuration is visible, and on obscure stacks, where automated insight has to be supplemented by human capture. A tool pitched as having no limits is the trap this whole argument accuses others of.

When this comes up. Comes up when a security review is already blocking a purchase, under a sovereignty policy, or after a vendor has been rejected on data egress.

How it is delivered

This is a condition applied to all of them rather than a module. Canvas is the part it constrains most, and Vault records that the constraint held. Each module is a fixed deliverable behind a go or no-go gate, and the baseline earns the design. The full set of modules is here.

Related situations

Tell us what you are trying to land.

A short conversation about your situation and whether an independent accountable role is the right instrument. If it is not, we will say so. No deck follows automatically.

Start a conversation