02 How we operate
How ARIA governs an enterprise rollout
From data handling to contracts, every part of an ARIA rollout is designed to pass security review and satisfy legal, IT and procurement. The summary below is what most enterprise teams ask us to walk through first.
Data governance
Your data stays yours
ARIA acts as your data processor under a signed Data Processing Agreement. You decide which sources are connected, how long conversations are retained, and when they are deleted. Export and erasure are self-serve.
Your content and conversations are never used to train shared or third-party models. Processing is isolated to your tenant, and model providers operate under contractual no-retention terms.
Identity & access
Least privilege by default
Authenticate through your own identity provider with SSO and SAML, including Okta, Microsoft Entra ID and Google Workspace. Role-based access control and granular permissions keep every user scoped to what they should see.
All administrative and data events are written to an immutable audit log that can be streamed to your SIEM. Encryption is enforced in transit with TLS 1.2 or higher and at rest with AES-256.
Deployment & residency
Run it inside your boundary
Choose a managed region in the EU or US, deploy into your own VPC, or run fully on-premise. Content and conversations never leave the boundary you select.
Private networking, IP allow-listing and customer-managed encryption keys are available for teams with stricter network and key-management requirements.
Retrieval & knowledge
Grounded, permission-aware answers
A retrieval-augmented generation pipeline is tuned to your corpus, with citation control and confidence thresholds, so ARIA answers from your sources or says it does not know.
Structured and unstructured sources are unified into one governed knowledge base. Document-level permissions mirror your own, so users only ever receive answers they are entitled to see.
Assurance & contracts
Paper that passes review
We support the documents enterprise procurement expects: a Master Services Agreement, Data Processing Agreement, mutual NDA, and completed security questionnaires such as SIG and CAIQ.
Service levels are defined in writing, with uptime commitments, response and resolution targets, and a documented incident response and breach notification process.
Partnership & support
A team, not a ticket queue
Every enterprise engagement includes a named engineering contact, an architecture review mapped to your stack, and a staged rollout plan from guided pilot to production.
Commercials are built for the enterprise too: annual or multi-year agreements, consolidated invoicing, volume pricing, and scheduled business reviews.