— Deployment

Pilot in days. Production in weeks.

Three deployment shapes. One transparent control plane. Most enterprises are catching real PII events before the legal review on their MSA finishes.

analytics

Structured event taxonomy

Standardized event types for easy correlation and faster incident response.

lock_clock

Immutable audit trail

Insert-only logs with e-signatures and timestamps for legal and compliance review.

public_off

Data residency options

US, EU, CA, AU residency choices to meet regional regulatory requirements.

We are adaptable and always secure.

gpp_good

SaaS Multi-Tenant

Defog-operated infrastructure on AWS. Your tenant data is logically isolated with row-level security and per-tenant encryption keys. No shared compute for policy evaluation. Compliance data stays in your chosen AWS region (us-east-1, eu-west-1, ap-southeast-2). Fastest time to value: under 20 minutes from sign-up to first policy active. Governed by Defog's SOC 2 Type II + ISO 27001 controls. Ideal for: companies without an infosec team yet, or SMBs who need enterprise protection without enterprise overhead.

lock

Dedicated Tenant

Your own compute resources, Defog-managed. No shared infrastructure at any layer. Your encryption keys (BYOK via AWS KMS, GCP KMS, or Azure Key Vault) — we never hold them. Your network perimeter: VPC peering or PrivateLink to your stack. Your audit logs live in your S3 bucket, not ours. Control plane managed by Defog so your team doesn't carry operational burden. Ideal for: regulated industries (finance, healthcare, defense), companies with data residency mandates, or security teams that need to show procurement "we don't share compute with anyone."

smart_toy

Self-Hosted / Sovereign

Defog runs entirely inside your infrastructure. Air-gapped deployment supported. Your hardware, your operating system, your network — we provide the binary or container image signed with our release key. Updates are your decision and your schedule. We provide a support SLA but the system operates without calling home. Zero telemetry leaves your perimeter unless you explicitly configure SIEM forwarding. Ideal for: government agencies, defense contractors, financial institutions under sovereign cloud mandates, and organizations where the phrase "the vendor can see our data" is a non-starter.

Reference rollout · 90 days

  1. 01

    Week 1 — Seed users + policy baseline

    Identify 5–15 seed users across your highest-risk roles: executives, legal, finance, M&A, and anyone who accesses regulated data. Install the browser extension or deploy the OS agent via your existing MDM. Enable the baseline policy pack — it covers the 40 most common AI exposure vectors without requiring any customization. First detection events appear in your Defog dashboard within minutes of installation.

  2. 02

    Week 2 — Tune and expand

    Review Week 1 detections with your security team. The baseline policy will surface false positives — typically 5–10% in enterprise environments. Use the policy editor to add site-specific exceptions, adjust confidence thresholds, and define your acceptable-use list. Expand rollout to 10–20% of the organization. Connect your SIEM: send OCSF-formatted events to Splunk, Sentinel, Elastic, or any webhook destination.

  3. 03

    Week 3 — SIEM integration + reporting

    Full SIEM pipeline validated. Evidence pack generated for your first audit review — SOC 2, ISO 27001, or HIPAA-mapped depending on your compliance program. Governance team reviews the weekly summary dashboard. Add your second approval layer: time-boxed exceptions for power users who need temporary access to blocked AI tools. Document the approval workflow in your policy version control.

  4. 04

    Week 4 — Full org rollout

    Phased rollout to 100% of devices in scope. Automated onboarding via SCIM + SSO means no per-user setup. Policy is version-controlled in Git — every change has an author, a timestamp, and a reviewer. Your CISO has a live governance dashboard with audit-ready export on demand. You are now operationally compliant with NIS 2 Article 21 and DORA TPRM requirements for AI vendor oversight.

What gets deployed

Browser extension
Chrome · Edge · Firefox · Safari · MDM-pushed
OS agent
macOS 12+ · Windows 10/11 · Ubuntu 20.04+ · sub-3% CPU
Network proxy (opt)
For unmanaged endpoints · Zscaler/Netskope/Palo Alto integration
Control plane
SaaS · dedicated · self-hosted · helm + terraform
SIEM forwarder
OCSF/CEF/LEEF/JSON · HEC, syslog, Kafka, gRPC

What you do not deploy

  • Nothing on your endpoints that isn’t already there (we ship as a managed extension/agent — same channel as your EDR)
  • No proxy MITM unless you ask for it — inspection happens client-side
  • No new IDP — we federate to yours
  • No new SIEM — events land in the one you already pay for
  • No new ticketing system — Jira/ServiceNow webhook in 5 minutes

Three planes. One control surface.

Edge plane (browser extension + OS agent + optional network proxy) inspects prompts and responses inline. Control plane (your cloud or ours) holds policy, identity, and audit log. Telemetry plane streams OCSF events to your SIEM in real time. Each plane fails open or closed by policy — your choice, per data class.

Walk through your deployment shape with an engineer.

Book a deployment scoping call