Control without lock-in.
Know where systems run, which providers are involved, how data moves, who is responsible, and how the system can be transferred or brought in-house if needed.
For every deployment, Cytria defines the agreed data perimeter, external dependencies, access rights, human validation points, logging requirements, and transfer conditions before production.
Swiss-hosted, client-controlled or deployed in an agreed private environment, depending on the system.
Execution Flow & Data Boundary
No calls to external AI APIs in the default configuration; all processing executes within the defined perimeter.
Deployment Postures
1. Client On-Premise (Existing Hardware)
The AI system is installed directly on the client's existing server infrastructure and graphic processing units (GPUs).
2. Client On-Premise (Acquired Hardware)
Cytria specifies and supports the acquisition of dedicated GPU hardware owned outright by the client.
RTX 4000-class: small teams, single workflow · RTX 6000-class / DGX: larger teams, concurrent systems.
3. Dedicated Swiss Hosting
Isolated environment set up on Infomaniak's servers, an independent Swiss hosting provider with public environmental commitments (renewable energy, reuse of datacenter heat, according to commitments published by Infomaniak).
Security Control Measures
| Control Domain | Cytria Specifications & Protocols |
|---|---|
| Access Rights & SSO | Enterprise SSO integration (OpenID Connect / LDAP); granular user role management and folder-level isolation. |
| Logging & Audit | Complete local logging of queries, indexed items, and human approvals. Default log retention of 90 days. |
| Human Validation | Process control interface: no email sending or writing action is performed autonomously. Assistants generate drafts submitted for review. |
| Backup Policy | Daily encrypted backups (AES-256) retained for 30 days within the secure deployment perimeter. Recovery procedures tested quarterly. |
| Updates & Patches | Scheduled monthly maintenance window. Application of critical security patches within 72 hours. Model changes are never applied silently. |
| Sub-processors | On-premise deployments: No sub-processors have access to client data. Hosted deployments: Infomaniak only. |