Skip to main content
Pavo supports multiple deployment options for teams with different requirements around data residency, compliance, and cloud control. It is the same product with the same security model in every option — the difference is where the platform runs, who operates it, and where your data lives.

Options at a glance

  • Pavo Cloud (SaaS) — Pavo hosts and operates the entire platform in its managed cloud (GCP). Multi-tenant, with each organization in its own isolated namespace. The fastest path: nothing for your infra team to run, live the week you connect.
  • Customer VPC (BYOC) — Pavo deploys and operates the entire platform — including every supporting store (database, cache, queues, object storage) — inside your own AWS or GCP account. Single-tenant, encrypted with your keys, no customer-data egress by default.
  • Hardened VPC — a stricter profile of the VPC deployment for highly regulated industries. Every service is self-hosted inside your VPC, no third-party integrations are deployed, and no customer data leaves your network.
In every option, ingestion is read-only — connectors pull from your sources and nothing is ever written back to your systems — and no customer data is ever used to train models, by Pavo or by any model provider.

Comparison

How to choose

  • Choose Pavo Cloud when you don’t need a customer-owned data boundary and want the fastest path with zero cloud operations.
  • Choose Customer VPC when your data must remain in your own cloud account, but you want Pavo to operate the deployment. You keep the cloud boundary, billing, keys, and governance; Pavo handles provisioning, upgrades, and operations.
  • Choose Hardened VPC when policy or regulation prohibits any third-party processing of your data. Every service is self-hosted inside your VPC and the deployment runs with only the bare-minimum sub-processors.
In all VPC deployments, Pavo operates under your access controls: there is no standing access to your environment, and support access is time-boxed, authorized, and audited.

Next steps

Pavo Cloud (SaaS)

Architecture, tenancy and isolation, and what runs where.

Customer VPC (BYOC)

What you provide, how provisioning works, and the hardened profile.

Security

Certifications, data handling, controls, and sub-processors.