Security
Your production data, on ground you choose
ewake deploys two ways. Both keep your data in Europe, both are read-only until you decide otherwise, and neither ever trains a model on what it sees. The difference is where the reasoning happens.
Model 01
SaaS, on EU infrastructure
Multi-tenant, with hard segregation between tenants. Telemetry is partitioned per account at the storage and query layer: nothing is pooled, joined or read across account boundaries.
Segregated per tenant
Your data is isolated to your own account and reachable only under your own credentials. No shared table holds two customers' telemetry side by side.
Processed in Europe, then discarded
Analysis runs on EU infrastructure and nothing crosses the Atlantic. The conclusion is kept; the raw telemetry behind it is thrown away once the investigation is written.
Never used to train a model
Your telemetry, your code and your incidents are never fed into training or fine-tuning: not ours, not a provider's. There is no exception and no opt-out to manage.
Model 02
BYOC, inside your cloud account
ewake runs in your own AWS, GCP or Azure account. Production data is reasoned over where it already lives, so it never transits onto our infrastructure at all.
No production data transmitted
Logs, traces, metrics and source stay inside the network boundary you already trust. What leaves, if anything, is operational metadata you can enumerate.
Your IAM, your VPC, your audit trail
Access is granted from your side and revoked from your side: a change you make, not a support ticket you file. Every action lands in your own logs.
The same agent, not a cut-down one
BYOC runs the full loop: take the page, investigate, open the pull request, watch the release. The rules you set govern it identically in either model.
Why BYOC
What enterprises are actually buying with BYOC
Data sovereignty stopped being a paperwork exercise the moment a company began operating across more than one jurisdiction. BYOC answers it where it is actually settled: at the infrastructure layer.
Sovereignty is a jurisdiction question, not a datacentre question
Article 83(5) of the GDPR sets the ceiling at €20 million or 4% of worldwide annual turnover, whichever is larger. Since 12 September 2025, the EU Data Act has separately obliged cloud providers to clear the obstacles that stop a customer moving their data elsewhere.
Pulling the other way is the US CLOUD Act of 2018, which lets US authorities compel a provider under US jurisdiction to produce data it holds, including data sitting on European disks. So two facts matter independently, and they are often confused: where your data physically rests, and whose law your vendor answers to.
Fewer boundaries for the data to cross
IBM put the global average cost of a breach at $4.99 million in its 2026 report, a 12% rise year over year. What moves that number for a given company is how far its sensitive data travels and how many parties end up holding a copy.
BYOC is not automatically safer than a well-built SaaS deployment, and we would not claim it is. What it changes is arithmetic: it removes a trust boundary. Production telemetry routinely carries PII, internal hostnames, IP addresses and raw SQL; keeping that inside one perimeter is a smaller target than keeping it inside two.
Ask what the vendor can actually do in your account
BYOC means different things to different vendors. Some want broad IAM roles, write permissions, or an inbound connection into your network in order to run their software next to your systems.
A tight design asks for operational metadata and stops there. Worth putting to any vendor, us included: which permissions exactly, read-only or not, and can your own team audit every action from your own logs. Our full permission list is published in the docs.
Trust and compliance
At ewake, security and compliance are foundational to how we build and operate. We maintain a strong compliance posture with SOC 2 Type II certification and GDPR compliance, while continuously evolving our framework to meet the needs of our customers. We work closely with each customer to understand and support their specific regulatory, security, and data protection requirements.
Trust CenterBring your security review to us
DPA, sub-processor list, pen-test report and the data-flow diagram are available on request. Ask us the hard questions before the trial, not after.
