> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pavoai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Overview

Pavo supports multiple deployment options for teams with different requirements around data residency, compliance, and cloud control. It is the same product with the same security model in every option — the difference is where the platform runs, who operates it, and where your data lives.

## Options at a glance

* **Pavo Cloud (SaaS)** — Pavo hosts and operates the entire platform in its managed cloud (GCP). Multi-tenant, with each organization in its own isolated namespace. The fastest path: nothing for your infra team to run, live the week you connect.
* **Customer VPC (BYOC)** — Pavo deploys and operates the entire platform — including every supporting store (database, cache, queues, object storage) — inside your own AWS or GCP account. Single-tenant, encrypted with your keys, no customer-data egress by default.
* **Hardened VPC** — a stricter profile of the VPC deployment for highly regulated industries. Every service is self-hosted inside your VPC, no third-party integrations are deployed, and no customer data leaves your network.

<Note>
  In every option, ingestion is **read-only** — connectors pull from your sources and nothing is ever written back to your systems — and **no customer data is ever used to train models**, by Pavo or by any model provider.
</Note>

## Comparison

|                                       | Pavo Cloud (SaaS)                                                                                                         | Customer VPC (BYOC)                                                                                             | Hardened VPC                                                     |
| :------------------------------------ | :------------------------------------------------------------------------------------------------------------------------ | :-------------------------------------------------------------------------------------------------------------- | :--------------------------------------------------------------- |
| **Where it runs**                     | Pavo's managed cloud (GCP)                                                                                                | Your own AWS or GCP account, inside your VPC                                                                    | Your own AWS or GCP account, inside your VPC                     |
| **Tenancy**                           | Multi-tenant — each organization in its own isolated namespace, with dedicated data stores, search indices, and endpoints | Single-tenant — the entire platform deployed inside your account                                                | Single-tenant                                                    |
| **Operated by**                       | Pavo — nothing for your infra team to run                                                                                 | Pavo, inside your account, under your access controls                                                           | Pavo, inside your account, under your access controls            |
| **Infrastructure provisioning**       | None — live the week you connect                                                                                          | Pavo's control plane provisions into your account on an agreed plan                                             | Same, with a stricter deployment review                          |
| **Encryption keys**                   | Pavo-managed; customer-managed keys (CMEK) available                                                                      | Your customer-managed keys (CMEK)                                                                               | Your customer-managed keys (CMEK)                                |
| **Search, workflows & observability** | Elasticsearch, Temporal, and Grafana as managed services, each under a DPA                                                | Your choice per service: self-hosted in your VPC (one-click) or the managed cloud version from your own account | Self-hosted inside your VPC only                                 |
| **Model inference**                   | OpenAI / Anthropic under zero-data-retention (ZDR) agreements                                                             | In-account (AWS Bedrock / Vertex AI) by default; external ZDR APIs if you enable them                           | In-account only (AWS Bedrock / Vertex AI)                        |
| **Customer-data egress**              | To disclosed sub-processors only, under DPA                                                                               | None by default — any egress is a choice you make, from your own account                                        | None                                                             |
| **Optional integrations**             | Disabled unless enabled; individually gated                                                                               | Disabled unless enabled; individually gated                                                                     | Not deployed                                                     |
| **Operational burden**                | None                                                                                                                      | Low — Pavo operates the deployment; you own the account and governance                                          | Low, with stricter change control                                |
| **Best fit**                          | Fastest path to a first validated improvement                                                                             | Data must stay inside your own cloud boundary                                                                   | Regulated industries — healthcare, insurance, financial services |

## How to choose

* Choose **Pavo Cloud** when you don't need a customer-owned data boundary and want the fastest path with zero cloud operations.
* Choose **Customer VPC** when your data must remain in your own cloud account, but you want Pavo to operate the deployment. You keep the cloud boundary, billing, keys, and governance; Pavo handles provisioning, upgrades, and operations.
* Choose **Hardened VPC** when policy or regulation prohibits any third-party processing of your data. Every service is self-hosted inside your VPC and the deployment runs with only the bare-minimum sub-processors.

In all VPC deployments, Pavo operates under your access controls: there is no standing access to your environment, and support access is time-boxed, authorized, and audited.

## Next steps

<CardGroup cols={3}>
  <Card title="Pavo Cloud (SaaS)" icon="cloud" href="/deployment/pavo-cloud">
    Architecture, tenancy and isolation, and what runs where.
  </Card>

  <Card title="Customer VPC (BYOC)" icon="server" href="/deployment/customer-vpc">
    What you provide, how provisioning works, and the hardened profile.
  </Card>

  <Card title="Security" icon="shield" href="/security/overview">
    Certifications, data handling, controls, and sub-processors.
  </Card>
</CardGroup>
