However strict your data-handling needs, Observant can meet them one of two ways: a SOC 2 Type II managed offering, or a fully self-hosted deployment inside your own environment. This note explains both — what each protects, what it asks of you, and how to choose — so you can tell us which fits and we'll formalize it for your account.
Both paths are offerings we will build to your selection, not shelf products — we're presenting them so you can choose the model before we commit the work. The security foundation in §1 is already live in the product today; each path hardens and formalizes it in a different direction. We will not represent a certification as complete until an independent auditor has issued it.
Whichever path you choose starts from the same baseline — the security posture already engineered into Observant. Stating it plainly, because it's what both options extend:
What differs between the two paths is where your data lives and who attests to the controls around it.
You keep using Observant exactly as it runs today; an independent auditor verifies our controls and gives you a report your security team can rely on.
Observant undergoes a SOC 2 Type II examination by a licensed CPA firm. Unlike a point-in-time snapshot, Type II observes our controls operating over a period (typically 6–12 months) and reports whether they were designed and functioning effectively throughout. Your data continues to live in Observant's managed cloud; what changes is that a neutral third party — not just us — attests to how it's protected.
Your data remains in Observant's multi-tenant managed environment, logically isolated to your organization and protected by the §1 foundation, now placed under audited controls: formal access management, change control, encryption verification, vendor management, monitoring, and incident response. You gain assurance and a paper trail; you don't take on hosting.
Very little: sign the DPA, and (optionally) review our SOC 2 report under NDA once issued. No infra, no operators, no deployment.
The whole system deploys into your cloud account or data center; your users' data never leaves your perimeter, and you hold the keys.
We package Observant as a deployable stack you run in your own infrastructure — single-tenant, isolated to you. The database, the application, and the engine all live in your environment, under your network controls, your IAM, and your encryption keys. Observant provides the software, the installer, and support; you own the perimeter.
Our stack is built on portable, open foundations, which is what makes a genuine self-host offering credible rather than aspirational: the database and auth layer (Supabase) is open-source and self-hostable; the engine already ships as a container image; the web app is static assets that serve from anywhere. There is no proprietary managed service at the core that can't be relocated.
A real infrastructure commitment: a cloud account or data center able to run containers, a Postgres database, a Redis instance, and a static host; someone to operate it (or a managed-deploy arrangement with us); DNS and TLS certificates; a secrets store; and your own accounts (or approval to use ours) for the outbound AI/email/voice services. Version upgrades are applied on a cadence we support but you schedule.
| Path A — SOC 2 (managed) | Path B — Self-hosted | |
|---|---|---|
| Where data lives | Observant's managed cloud, isolated to your org | Entirely inside your environment |
| Tenancy | Multi-tenant, logically isolated | Single-tenant, physically separate |
| Who holds encryption keys | Observant (managed, audited) | You |
| Independent attestation | SOC 2 Type II report | You audit your own deployment; we supply architecture & control docs |
| Your infrastructure effort | None | Meaningful — you run the stack |
| Your ongoing ops burden | None | You operate & schedule upgrades (with our support) |
| Data residency control | Region selectable; provider-bound | Fully yours |
| Time to onboard | Immediate once the report is issued | Weeks, scoped to your environment |
| Outbound AI processing | Via Observant's vendor agreements | Your vendor agreements, or self-hosted model |
| Commercial shape | Enterprise tier | Custom engagement: license + deployment + support |
| Best for | Most teams wanting assurance without ops | Regulated / residency-bound teams with a platform function |
Both paths inherit the entire §1 foundation. The table shows only where they diverge.
If you're unsure, four questions usually settle it. Send us your answers and we'll come back with a recommendation and a scope.
Regulatory constraints. Are you bound by a framework or contract that dictates where data may reside or who may process it (e.g. HIPAA, GDPR residency, FedRAMP-adjacent, internal "no third-party cloud" policy)?
Assurance vs. control. Does your security team need an independent report (points to Path A), or must the data physically stay in your environment (points to Path B)?
Operational capacity. Do you have a platform/DevOps team that can run and maintain a deployment? If not, Path A avoids that burden entirely.
Timeline. Do you need to move now (Path A, once the report is available, or an interim bridge — see §5), or can you scope a deployment over a few weeks (Path B)?
Observant is an AI product: to conduct interviews and synthesize insight, conversation text is sent to a large-language-model provider. We're explicit about this because it matters to a security review.
On Path A, these run under Observant's vendor agreements and appear on the SOC 2 subprocessor list. On Path B, you can bring your own provider accounts (or, for the strictest cases, a self-hosted model) so that even outbound processing runs under your agreements. A fully air-gapped deployment is possible with a self-hosted model, at some cost to interview quality — we'll scope that honestly if you need it.
Either way, the answer to "is Observant safe for our users' data?" is yes — the two paths simply let you choose the shape of that safety.