Your data, your control
however you deploy Grengin
Bring your own API keys, get full audit trails, and verify the code yourself. Grengin does not train models on your business data.
Built for security-conscious teams
Every feature designed with enterprise security requirements in mind.
Data Encryption
All data encrypted at rest (AES-256) and in transit (TLS 1.3). Your conversations are protected end-to-end.
No Training Guarantee
Grengin does not use your business data to train models. With your own API keys, model-provider processing is governed by your agreements with those providers.
Secure Infrastructure
Hosted on AWS. AWS holds SOC 2 Type II for its data centers; Grengin itself is not yet SOC 2 audited.
Access Controls
Role-based access, SSO integration, and granular permissions. Control exactly who can do what.
Audit Logging
Complete audit trails of all AI interactions. Export logs for compliance reviews and investigations.
PII Protection
Automatic detection and optional redaction of sensitive information before it reaches AI models.
Self-host, Grengin Cloud, or Enterprise: the security trade-offs
Same software on every path. Here is what changes when we operate the infrastructure for you.
| Question | Self-host | Grengin Cloud (Starter and Pro) | Enterprise |
|---|---|---|---|
| Where does the app run | In your AWS account, in the region you pick. | In our AWS account, on shared infrastructure, in the region you pick. | Dedicated. Isolated in our cloud, or inside your own cloud account, on any provider. |
| Is Grengin in the data path | No. Requests go directly to your AI providers without passing through Grengin. | Yes. We operate the app, so your traffic passes through it. | In our cloud, yes. In your account, no: the app runs in your tenant and requests go straight to your providers. We operate it through an access role you grant and can revoke. |
| Where are model keys | In your tenant. You hold them; we never see them. | Stored encrypted in our vault. Still your keys, still your provider bill. | In your tenant for in-account deployments, in our vault for hosted ones. Always your keys, always your bill. |
| What it costs | Free. You pay your cloud and your model providers, nothing to us. | Free for up to 10 users. Past 10, every active user is $1.25 per month. Plus your model providers, never marked up. | From $500 per month, billed quarterly, for a managed dedicated deployment; larger deployments are quoted on users and requirements. Plus your model providers, never marked up. |
| Who patches it | You do, when you pull a new image. Old versions keep working. | We do, continuously. You are always on the current release. | We do, in maintenance windows you agree to. |
| Support | Community. | Community on Starter, email on Pro. | Dedicated contact with an SLA. |
| Audit log retention | Your storage, your rules. | 30 days on Starter, one year on Pro. | Custom. |
| Proof of no lock-in | Same image, same schema, same export as Cloud. Read the source. | One-click export into your own cloud. Your data comes with you. | Same image, same schema. In-account deployments are already in your cloud. |
Grengin is never in the data path
The image runs in your account. Prompts, documents, embeddings and logs are written to storage you own, in the region you picked. There is no tunnel back to us.
Deploy Now- Prompts and completions go straight from your instance to the model provider you chose.
- Model keys live in your own secret store. We hold no copy and have no way to read one.
- Audit logs and chat history are rows in your database, queryable with the tools you already run.
- The only call home is an optional version check, and you can switch it off.
We operate the app, so we are in the data path
Stated plainly rather than buried. Your traffic passes through systems we run, and everything below exists to make that a decision you can audit instead of a leap of faith.
Eject whenever you like: one-click export into your own cloud, same schema, your data comes with you.
- Your workspace runs in our AWS account, in the region you choose when you sign up.
- Model keys are stored with envelope encryption and used only to serve your workspace.
- Sub-processors are listed publicly and a DPA is signed before your first prompt.
- No SOC 2 report yet. When there is one it will be linked here, not described.
The Grengin Data Guarantee
Grengin does not use your business conversations to train models. You bring your own API keys and control which model providers process your requests.
- Model-provider processing is covered by your direct agreements with each provider
- Review each provider's training and retention terms before connecting a key
- We'll sign a Data Processing Agreement (DPA) on request
Security architecture
Built on AWS with defense-in-depth security practices. Multiple layers of protection ensure your data stays safe.
- Network Security: VPC isolation, WAF, DDoS protection
- Application Security: Regular penetration testing, dependency scanning
- Data Security: Encryption at rest and in transit, key rotation
- Access Security: Zero-trust architecture, privileged access management
- Monitoring: Security monitoring and automated alerting
AI Governance and Security:
Frequently Asked Questions
How we store, protect, and handle your data—expand any question for the full answer.
Data Handling & Privacy
Where is my data stored?
Depends on how you run Grengin. Self-host the marketplace image (or build from source) and everything lives in your own AWS account, in the region you pick—we never see it. On Grengin Cloud, your workspace runs in our AWS account, in the region you choose at signup.
How long is data retained?
On self-host, retention is entirely up to you—it's your database and your storage. On Grengin Cloud, conversation history is retained until you delete it. You can delete data at any time, and we purge it from our systems within 30 days of deletion.
Who has access to my data?
Self-host: no one at Grengin, ever—we have no credentials to your instance. Grengin Cloud: only authorized employees with a legitimate business need, and all access is logged. Neither path shares data with third parties beyond what's needed to serve the request (e.g., sending your prompt to the model provider you chose).
Is my data used for AI training?
Grengin does not use your conversations to train models. You bring your own API keys, so review the training and retention terms of each provider you choose. The same applies whether you self-host or use Grengin Cloud.
What happens if there's a breach?
On self-host, a breach of the underlying cloud account is between you and your provider—Grengin was never in the data path to breach. On Grengin Cloud, we have incident response procedures in place and will notify affected customers within 72 hours as required by GDPR, and we will publish our incident-response summary on request.
Can I switch between self-host and Grengin Cloud?
Yes, in either direction. Export from Cloud and run the same image in your own account, or start self-hosted and move to Cloud later if you'd rather stop operating infrastructure. Same schema, same software, your data comes with you.
Ready for a security review?
Our security team is standing by to answer your questions and provide documentation.