Your team’s only setup work is pointing Pavo, read-only, at your sources and configuring SSO — roughly half a day of infra effort, all front-loaded in the first week.
Tenancy and isolation
Pavo Cloud is a multi-tenant platform with per-organization isolation. Each organization runs in its own isolated namespace, with dedicated data stores, search indices, and endpoints. Your organization’s data is never shared with, or visible to, another tenant.- Encrypted at rest (AES-256 via cloud KMS) and in transit (TLS 1.2+); customer-managed encryption keys (CMEK) available on request.
- No public data endpoints; network isolation throughout.
- Sign-in runs through your identity provider via SSO (OIDC).
Architecture
Figure — Pavo Cloud: multi-tenant platform with per-organization isolation; managed sub-processors under DPA. The sandbox runs agent-generated code behind a default-deny egress allowlist proxy — outbound access is limited to an agreed allowlist (open-source package registries by default), and everything else is blocked. See Security → Network & egress.Components
Sub-processors in this deployment
Pavo Cloud uses a defined set of managed services that process data on Pavo’s behalf, each disclosed and under a DPA: Elasticsearch, Temporal, and Grafana (core platform services), Zitadel, Amplitude, and Brevo (supporting services — no customer business data), and OpenAI / Anthropic for inference under zero-data-retention agreements. Optional integrations (Modal, Langfuse, Parallel) are individually gated per instance and disabled unless you enable them. See the full list, with the data each one processes, in Sub-processors.What you provide
- Read-only credentials for the sources you connect (warehouse, code repositories, experimentation platform, dashboards, documentation).
- SSO configuration through your identity provider (OIDC).
Next steps
Customer VPC (BYOC)
Need the platform inside your own cloud boundary? Run it in your VPC.
Security
Certifications, data handling, controls, and the full sub-processor list.