Nodes-managed cloud deployment.
Data, model access, isolation, retention, and telemetry are defined inside a Nodes-managed operating boundary and the customer agreement.
Deploy Nodes in Nodes Cloud, inside a single-tenant customer VPC, or on customer-managed on-premises infrastructure. The selected boundary defines where data, models, agents, workflows, traces, and telemetry may operate.
SOC 2 Type II attested · HIPAA and GDPR aligned · Named human authority · Review scope and evidence
Deployment flexibility is a platform capability. Security claims must follow the selected boundary, so each option is described separately.
Data, model access, isolation, retention, and telemetry are defined inside a Nodes-managed operating boundary and the customer agreement.
Run the platform inside an approved AWS, Azure, or GCP boundary with customer-specific weights and private data paths.
Run the platform, models, agents, workflows, and Decision Traces inside an approved on-premises environment.
Private VPC and on-premises configurations can keep customer production records and customer-specific intelligence inside the approved customer boundary. Verify all model, connector, and operational paths.
The SOC 2 Type II report is available under NDA. HIPAA and GDPR describe operational alignment, not certifications. Each deployment requires review of its configuration, customer obligations, and applicable agreements. Inspect the scope and materials.
Nodes works within configured permissions. Actions requiring approval remain gated by the customer's policy. Named people control consequential decisions and changes to production workflows; routine steps can continue within an already approved scope.
The broader platform design links evidence, model and policy versions, human questions and edits, approval state, action, and later outcome in a Decision Trace. Ask to inspect those fields in the proposed application. The current insurance evidence does not establish the full autonomous runtime or automated learning loop.
Test permission revocation, a changed plan after approval, and a partially completed action. Agent-run history should account for execution; operational telemetry must not be the only record of a business decision. Customer-designated workflows can require a second signer.
The connector design uses proposed field mappings, visible uncertainty, and human verification. Require a demonstration that a renamed or drifted field stops flowing instead of being guessed at. Automatic discovery and repair coverage must be established for the proposed environment.
Use existing authentication and least-privilege scopes for every connected system.
Record why each source field maps to a canonical definition and where confidence is limited.
Require an approval record before uncertain evidence enters a decision program.
Pause the affected flow and route the change for review instead of silently remapping it.
The same Fortune 500 insurance deployment moved from contract to production in 34 days. These observed results describe one customer environment and do not promise the same timeline elsewhere.
The customer retains separable customer-specific intelligence defined in the agreement: source evidence, graph relationships, context models, human judgments, Decision Traces, outcomes, and applicable learned artifacts. Customer-specific weights and calibration artifacts are included where they exist and the agreement defines them.
Practical portability needs a sample export. Ask which records it contains, how identifiers and relationships survive, which schemas and provenance come with it, and what remains usable without Nodes. Agree retention, formats, transition support, and any release or escrow terms before production.
Customer ownership does not provide indefinite use of Nodes' licensed runtime. Nodes retains its platform code and pre-existing reusable intellectual property; agent operation, connector maintenance, updates, and support follow the service agreement. Confidential company memory is not pooled across tenants by default.
These technical explainers remain available for security and procurement review.
Bring one repeated decision, the systems it crosses, the outcome you measure, and the boundary that governs it.