Security & deployment

Your project intelligence. Your infrastructure rules.

Anvil is designed around the security posture of the company it serves. Run it as a managed cloud service, isolate it in dedicated infrastructure, connect it to models you already approve, or host the models on servers you control.

Architecture, providers, data flows, permissions, retention, and approval boundaries are documented before production access.

anvil.securityDeployment profile
InfrastructureManaged, dedicated, or customer-controlledConfigurable
AI modelsApproved provider or self-hosted endpointControlled
Project accessExisting permissions plus Anvil rolesScoped
ActionsApproval gates and complete receiptsAuditable
RetentionDefined by data class and workflowDocumented
No one-size-fits-all architecture · controls follow the deployment

Choose the boundary

Deploy around your requirements—not ours.

The right boundary depends on the data, integrations, model policy, and internal controls involved. Anvil can support more than one deployment pattern across the same company.

01 · Managed

Anvil-managed cloud

The fastest path for a scoped workflow, with isolated application access, managed operations, and a documented provider chain.

Best for pilots and standard production workflows.
03 · Self-hosted AI

Models on your servers

Anvil can use a private model endpoint running on your servers, private cloud, or approved GPU infrastructure so model inference stays within the boundary you control.

Best for restricted data and approved-model programs.

Controls that follow the work

Security is part of the workflow design.

Identity SSO + project rolesAccess Least privilegeLifecycle Retention + deletion
Approved sourcesProject systemsFolders + mailboxesInternal standards
Controlled Anvil boundary

Only the approved workflow path

DataEncrypted + minimizedModelsAllowlisted or self-hostedWorkflowPermissions enforced
Controlled outcomesAnswerSource citedActionHuman approvalRecordReceipt retained
Audit trailRequest contextSources usedApprovalSystems changed

Connect without opening everything

Scoped access to the systems you already trust.

Anvil does not need a master key to the company. Each connector is scoped to the projects, records, folders, mailboxes, and actions required for the approved workflow.

Dedicated service identitiesAvoid shared personal credentials and define ownership.

Minimum connector scopesRead and write permissions separated where the platform allows it.

Secrets outside application codeKeys and credentials handled through deployment secret management.

Approval before consequential writesDraft first, then execute under the workflow's control policy.

Revocable accessConnections can be disabled without dismantling the source system.

What IT receives

A reviewable architecture before production access.

The blueprint turns security questions into explicit deployment decisions your technical and risk teams can review.

01

Architecture

Deployment boundary, environments, network paths, and system ownership.

02

Data flow

What enters Anvil, where it moves, what is stored, and what leaves.

03

Providers

Hosting, database, model, monitoring, and integration providers involved.

04

Permissions

Users, service identities, connector scopes, roles, and approval levels.

05

Lifecycle

Retention periods, cache and log handling, exports, backups, and deletion.

06

Operations

Monitoring, incident contacts, change control, recovery, and offboarding.

Direct answers

Questions your security team will ask.

Can Anvil run in our environment?

Yes. The application, data services, and model path can be designed for dedicated or customer-controlled infrastructure when required.

Can we host the AI models ourselves?

Yes. Anvil can connect to private model endpoints running on your servers, in your cloud account, or through an inference platform your company already approves.

Is our data used to train shared models?

Anvil does not use customer project data to train shared models. Third-party inference is limited to approved providers and data-use settings—or removed from the path by using a self-hosted model.

Can we require zero data retention?

Yes, when the selected model path supports it. We can enforce eligible zero-retention endpoints or keep inference inside customer-controlled infrastructure.

Does Anvil inherit our project permissions?

It can align access with identity, project membership, company, role, and source-system permissions, then add workflow-specific approval boundaries.

How do we complete a security review?

Start with the blueprint. We provide the architecture, data flow, provider list, permission matrix, lifecycle plan, and operating controls for the proposed deployment.

Bring your requirements

We can design the boundary before we connect the first system.

Send us your hosting, identity, model, retention, integration, or vendor-review requirements. We will map them into the first workflow and deployment plan.

Start a Security Review See How We Scope It

Security contact
chris@builtwithanvil.com