Skip to main content
Pavo Cloud is the managed deployment: Pavo hosts and operates the entire platform in its managed cloud (GCP, on GKE). There is no infrastructure for your team to stand up or run — the deployment is live the week you connect your sources.
Your team’s only setup work is pointing Pavo, read-only, at your sources and configuring SSO — roughly half a day of infra effort, all front-loaded in the first week.

Tenancy and isolation

Pavo Cloud is a multi-tenant platform with per-organization isolation. Each organization runs in its own isolated namespace, with dedicated data stores, search indices, and endpoints. Your organization’s data is never shared with, or visible to, another tenant.
  • Encrypted at rest (AES-256 via cloud KMS) and in transit (TLS 1.2+); customer-managed encryption keys (CMEK) available on request.
  • No public data endpoints; network isolation throughout.
  • Sign-in runs through your identity provider via SSO (OIDC).

Architecture

Figure — Pavo Cloud: multi-tenant platform with per-organization isolation; managed sub-processors under DPA. The sandbox runs agent-generated code behind a default-deny egress allowlist proxy — outbound access is limited to an agreed allowlist (open-source package registries by default), and everything else is blocked. See Security → Network & egress.

Components

Sub-processors in this deployment

Pavo Cloud uses a defined set of managed services that process data on Pavo’s behalf, each disclosed and under a DPA: Elasticsearch, Temporal, and Grafana (core platform services), Zitadel, Amplitude, and Brevo (supporting services — no customer business data), and OpenAI / Anthropic for inference under zero-data-retention agreements. Optional integrations (Modal, Langfuse, Parallel) are individually gated per instance and disabled unless you enable them. See the full list, with the data each one processes, in Sub-processors.

What you provide

  • Read-only credentials for the sources you connect (warehouse, code repositories, experimentation platform, dashboards, documentation).
  • SSO configuration through your identity provider (OIDC).
That’s the entire footprint — there is nothing to provision, patch, or scale on your side.

Next steps

Customer VPC (BYOC)

Need the platform inside your own cloud boundary? Run it in your VPC.

Security

Certifications, data handling, controls, and the full sub-processor list.