Security Comparison (at a glance)
What leaves your environment?
- SaaS: Runtime traffic remains in the selected region. Minimal controlâplane metadata is stored centrally; customer data (logs/metrics) retained per policy (90/365 by default) with zeroâretention and PII scrubbing options.
- Hybrid: Application data, prompts, responses, and logs stay entirely in your VPC/onâprem. Metrics are always emitted to Portkeyâs control plane (ClickHouse) and can be hosted in your region of choice. IP/URL redaction supported.
- Airâgapped (legacy â existing deployments only): No outbound network calls for any purpose (including licensing and updates). All data remains inside the isolated environment.
Data flows (per model)
SaaS Enterprise
- Control plane is centrally hosted (no customer data resides here).
- AI Gateway is deployed on regional edge; requests are served in the chosen region (e.g., EUâonly when EU is selected).
- Persistent data stores (logs, metrics) are created in the customerâs chosen region (e.g., separate EU shards for enterprise customers).
Hybrid (Recommended)
- Gateway runs inside your VPC/onâprem; prompts, responses, and logs never leave your environment.
- Operational metrics are always sent to Portkeyâs control plane (ClickHouse); the ClickHouse DB can be hosted in your region of choice.
- IP and URL redaction supported; dataâplaneâcontrolâplane connectivity can be Internet or private tunnel/VPC peering.
Airâgapped (Legacy â Not Offered)
- Fully disconnected deploymentâno outbound traffic required for licensing or updates.
- Container images are delivered via private registry or offline media; updates applied offline on your schedule.
Common security questions
Where does our data stay?
Where does our data stay?
SaaS: Customer data is stored in your selected region (e.g., EU). Runtime requests are served inâregion via edge gateways.
Hybrid: All prompts, responses, and logs remain in your VPC/onâprem stores that you control.
Airâgapped: All data remains entirely within your offline environment.
What does Portkey see?
What does Portkey see?
SaaS: Minimal controlâplane metadata and regionâpinned logs/metrics per your retention policy.
Hybrid: Only operational metrics are sent to Portkeyâs ClickHouse (always). IP/URL redaction supported. Your LLM logs explicitly reside in your databases; the control plane has no access to them.
Airâgapped: No outbound telemetry; Portkey receives nothing.
How do we handle PII and retention?
How do we handle PII and retention?
SaaS: Default retention is 90 days (logs) and 365 days (metrics). Zeroâretention and PII scrubbing are available; a metricsâonly mode is supported.
Hybrid/Airâgapped: Logs live in your S3/S3âcompatible store with your lifecycle and IRM policies. Fully offline for Airâgapped.
Secrets and KMS
Secrets and KMS
SaaS: Provider keys are stored in Portkeyâs vault with envelope encryption; KMS is supported (BYOK).
Hybrid/Airâgapped: Bring your own KMS (AWS KMS, Azure Key Vault, GCP KMS) for envelope encryption.
Identity, SSO, and RBAC
Identity, SSO, and RBAC
All models support SSO (SAML/OIDC), SCIM, and fineâgrained RBAC. Hybrid and Airâgapped include local gateway RBAC.
Network egress and connectivity
Network egress and connectivity
Hybrid: Outbound destinations are Portkey controlâplane public APIs and the container registry. Dataâplaneâcontrolâplane can be over the Internet or a private tunnel/peering. Controlâplaneâdataâplane can use a tunnel/peering as well.
Airâgapped: No egressâperiod.
SIEM and observability
SIEM and observability
Native exports (e.g., syslog/OpenTelemetry) and documentation are provided. In Hybrid/Airâgapped, all integrations run from your environment.
Compliance, pen tests, and subprocessors
Compliance, pen tests, and subprocessors
SOC 2 Type II and other certifications are available via the trust portal. Pen test cadence and reports are available. Subprocessors are published with a notification policy (SaaS); Hybrid exposure is minimal; Airâgapped has none.
Shared responsibility
Why Hybrid is the right choice
Data stays put
Enterprise velocity
Operational safety
References
- Hybrid deployment guide: GitHub (Helm)
- Trust & compliance portal: trust.portkey.ai
- Contact:
support@portkey.ai

