Options at a glance
- Pavo Cloud (SaaS) — Pavo hosts and operates the entire platform in its managed cloud (GCP). Multi-tenant, with each organization in its own isolated namespace. The fastest path: nothing for your infra team to run, live the week you connect.
- Customer VPC (BYOC) — Pavo deploys and operates the entire platform — including every supporting store (database, cache, queues, object storage) — inside your own AWS or GCP account. Single-tenant, encrypted with your keys, no customer-data egress by default.
- Hardened VPC — a stricter profile of the VPC deployment for highly regulated industries. Every service is self-hosted inside your VPC, no third-party integrations are deployed, and no customer data leaves your network.
In every option, ingestion is read-only — connectors pull from your sources and nothing is ever written back to your systems — and no customer data is ever used to train models, by Pavo or by any model provider.
Comparison
How to choose
- Choose Pavo Cloud when you don’t need a customer-owned data boundary and want the fastest path with zero cloud operations.
- Choose Customer VPC when your data must remain in your own cloud account, but you want Pavo to operate the deployment. You keep the cloud boundary, billing, keys, and governance; Pavo handles provisioning, upgrades, and operations.
- Choose Hardened VPC when policy or regulation prohibits any third-party processing of your data. Every service is self-hosted inside your VPC and the deployment runs with only the bare-minimum sub-processors.
Next steps
Pavo Cloud (SaaS)
Architecture, tenancy and isolation, and what runs where.
Customer VPC (BYOC)
What you provide, how provisioning works, and the hardened profile.
Security
Certifications, data handling, controls, and sub-processors.