Skip to content
MouseCat
Security

Security

Your data is scoped to your tenant and is never used to train global models. Security-sensitive customers can run the private cloud deployment: single-tenant in your own cloud account, customer-managed keys, no data egress, reviewable infrastructure-as-code.

Private cloud deployment

The five points.

  • Private cloud runs in your cloud account

    Single-tenant, dedicated per customer. No shared control plane. No commingling of customer data.

  • You own the data and the keys

    Encrypted at rest with customer-managed keys you can rotate or revoke. TLS 1.3 in transit.

  • No MouseCat traffic leaves your network

    The egress service reaches only your internal systems — your data platform, your model gateway.

  • You control access

    MouseCat's access is least-privilege, logged, reviewable, and revocable by you at any time.

  • Deployed as reviewable infrastructure-as-code

    You can read exactly what gets provisioned, and apply your own guardrails, logging, and security tooling.

Architecture

Layered controls around your data.

customer network · no egresscloud accountisolated networkboundarycomputeyour data
MouseCat runs inside a cloud account you own, on AWS, Azure or GCP. Its data sits at the centre, encrypted with your keys, and its only outbound connections are to systems you already own — nothing reaches the edge of your network, so nothing crosses it.
Controls

Governance and auditability.

Every decision is evidence-backed. Inputs, reasoning, and outputs are recorded with configurable retention. Conclusions cite the evidence they rest on, and every verdict is emitted with explicit reasoning. The result is a complete, reviewable audit trail for every case.

You retain decision authority — you decide what routes to human review and what's enabled for automatic action. The platform supports model validation, performance monitoring, and drift detection, along with the data lineage and documentation that model risk management requires of regulated institutions.

Division of duties

Shared responsibility.

AreaYouMouseCat
Cloud account & infrastructureOwn the account. Run the infrastructure under your existing controls and guardrails.Deliver the deployment as infrastructure-as-code you can read before it runs.
Identity & accessGrant, review, and revoke access at any time, through your own identity provider.Operate under least-privilege access that is logged and reviewable by you.
Customer dataOwn your data. It stays in your account throughout.Process it only inside your boundary. Never used to improve models for anyone else.
Encryption & keysHold the customer-managed keys. Rotate or revoke them on your schedule.Encrypt at rest under your keys. TLS 1.3 in transit.
Logging & monitoringOwn retention, access controls, and alerting in the systems you already run.Record every input, reasoning step, and output, and export traces to your destinations.
Incident responseDetect and respond in your account, on your existing escalation paths.Maintain documented runbooks and support the MouseCat components at your direction.
Documentation

Request the full architecture and security documentation.

The full reference architecture and security documentation is available to your security team under NDA. Tell us where to send it.