Enterprise

Your data stays yours, wherever you deploy

The whole platform rides on our single-binary native graph engine. It runs in managed cloud, private VPC, on-prem, or fully air-gapped, and idles at 14.5 MB where Neo4j needs 3,500 MB. Sovereignty is built into the architecture from the first line.

Security

Six defense-in-depth layers

Trust is enforced at the action boundary, not only at the perimeter. The strongest controls sit at the moment an agent attempts to do something.

01

Perimeter and Network

Zero-trust scopeSingle governed entry pointWAF and rate limitingTLS in transit everywhere
02

Identity and Authentication

SSO (OIDC/SAML)SCIM provisioningMFAShort-lived session tokens
03

Authorization and Tenancy

Five-role access modelDepartment isolationAttribute-based rulesLeast-privilege enforcement
04

Policy, Governance, Safety

Policy-as-code at boundaryHuman approval gatesPII/topic guardrailsAction budget circuit-breaker
05

Data Protection and Sovereignty

Classification at ingestionSovereignty routingSecrets in your KMSTenant data isolation
06

Audit, Trace, Assurance

Hash-chained immutable auditFull data and action lineageCompliance evidence packsNever sampled

Access & control

Who can do what, decided once, enforced everywhere

Roles, departments, and policy live in one settings plane. Every agent and every user inherits the same rules.

Five-role access model

Super admin, department admin, power user, compliance officer, and developer. Each role maps to a bounded set of surfaces and actions. No shared admin accounts.

Access reviews become a single export.

Department isolation

Departments are hard boundaries. Agents, data, and policies stay inside their department. A department can tighten inherited grants but never loosen them.

One department's agents can never read another's context.

AI Policy

Policy rules decide what agents may read, write, and execute. Checked at the action boundary, before anything runs.

Risk appetite is set once and enforced everywhere.

Versioned AI Constitution

Org-level rules every agent inherits. Every change is recorded and attributable to a person.

Versioned like code. Auditors can diff what rules applied when.

Usage and cost tracking

Usage and spend tracked per agent, user, and department. Operations sees where the money goes before finance asks.

No surprise bills. Spend per team stays visible.

Billing

Billing reads the same usage numbers the console shows. One set of figures, no reconciliation between invoice and dashboard.

Consumption maps to department budgets.

Deployment

Three postures, one control plane

Deployment posture is a configuration switch on one codebase. The same single-binary engine runs in all three postures and boots in 411 ms even on local disk.

Cloud

Fully managed, SOC 2 region. Zero infrastructure overhead.

Same day

Private Cloud

Your VPC, your keys, your network boundary.

Single-binary deploy

Air-Gapped

Fully isolated cluster. Zero egress. All assets bundled.

2 to 4 weeks

Bulk Ingest

Your whole estate in before the coffee is cold

Our purpose-built graph engine loaded 15,000,000 nodes from a 5.1 GB dump in 56 seconds. One single binary, no cluster to stand up, and the same run works inside an air-gapped boundary.

wexa bulk ingest
INGESTING
$wexaingestestate-dump.tar(5.1 GB)
0nodes written|t+0 s
▸2,100,000 nodessources scanned✓ ontology aligned
▸8,400,000 nodesrelationship edges linked✓ graph live
▸12,700,000 nodesindexes built✓ audit chain sealed
✓15,000,000 nodes in 56 sInternal benchmark, verified 2026-07

Benchmark run on Wexa's purpose-built graph engine, on a single binary with no external cluster.

Sovereignty

Bring your own everything

Bring your own cloud

A single binary deploys into your private cloud or cluster. Storage backends span in-memory, local disk, and MongoDB (Postgres and MySQL planned). No mandatory Wexa-managed dependency.

Bring your own secrets

Credentials live in your key-management system across four supported backends. Never in code.

Bring your own model

No hard-coded provider. The model registry routes across cloud and local models by data class and sovereignty.

Data residency

Cloud installs pinned to SOC 2 region. Private cloud and air-gapped keep all data inside your boundary.

FAQ

Enterprise deployment questions

Where does our data live?

Residency is a deployment-posture choice: managed cloud (SOC 2 region), private cloud (your VPC), or fully air-gapped. Sovereignty is enforced at the model-routing layer. Classified data never leaves your boundary.

How are tenants isolated?

Organization, department, project hierarchy. Every object carries its scope. Retrieval data is physically isolated per project. A department can tighten but never loosen inherited grants.

What compliance frameworks are mapped?

Control catalogs for SOC 2 (certification underway), ISO 27001 (control mapping in progress), GDPR, and EU AI Act alignment map to live evidence: traces, audit log, provenance, approval gates. Evidence packs are downloadable and chain-verifiable.

Can we bring our own models?

No provider is hard-coded. The registry supports hosted and bring-your-own models with sovereignty, cost, and latency routing. Restricted data pins to local models automatically.

Is audit ever sampled?

Never. Every consequential event emits an audit record. Non-consequential traces may be sampled to control cost, but audit events are never sampled.

What is the exit and portability story?

Bring-your-own models, on-prem option, audit and lineage export, downloadable evidence packs, and a documented REST/SDK surface. Wexa's graph engine speaks Bolt and Cypher, so graph data ports to or from Neo4j with a one-line change. Run entirely inside your boundary and take everything with you.

Enterprise deployment

Deploy in your environment, on your terms.

Book a 30-minute scoping call or send us a message. We respond within one business day.