The technical meeting is going well until someone from security asks the question that stops everything: where exactly will our company's data live? From there the conversation stops being about what the platform does and starts being about whose cloud account it runs in. That's the decision that separates the two deploy models for a context layer: BYOC, short for bring your own cloud, where the platform runs inside the company's own account, and the hosted model, where the vendor provisions and operates that account.
In the hosted model, the vendor opens a cloud account dedicated to the customer and operates everything inside it. On the company's side there's a console address and a login — no account to open and no cloud budget to approve.
In BYOC the platform runs inside the company's own account. The vendor delivers the infrastructure package, the customer's team applies it to their account, and operation continues with the vendor from there.
Everything else follows from that choice: who pays the cloud bill, whose network and security policies apply over the environment, and who needs to be at the table for the environment to go up.
Every customer has their own dedicated installation. No database, graph, index or queue shared between companies. It's the same version of the same software, laid out the same way, in both cases.
What runs inside it is a Company Brain, the layer that knows the company: what data exists, where it lives, how it relates, and who is allowed to see what. It's three pieces. A knowledge graph with the business entities. An ontology giving meaning to every term at that company. A semantic layer translating the question into a query with the correct permission. That context is served to models through MCP, an open protocol connecting models to data sources.
Keeping a single product was a deliberate choice. With a stripped-down edition on one side, the infrastructure decision would end up limiting what the company can do with its own context.
Inside the installation there are four places data lives: the relational database with metadata and state, the entity graph, the vector index for semantic search, and the lake with raw and processed data. In BYOC, all four sit in the customer's account.
That's the difference internal policy and regulators tend to require in writing. When the rule says data must sit in an account owned by the organization itself, the hosted model doesn't satisfy it, no matter how dedicated the environment is. It's a policy question, and legal, compliance or security are the ones who answer it.
With the account belonging to the company, the house's own rules apply over the environment, and the team audits it the same way it already audits the rest of that account.
This is the most expensive misunderstanding in the conversation, because plenty of companies rule out BYOC thinking they'll inherit a system to maintain.
The line of responsibility sits lower than assumed. The customer takes care of the cloud account, applies the infrastructure the first time, approves changes and pays the cloud bill. Installing and updating the platform, monitoring the environment's health and responding to incidents stay with the vendor in both models.
The initial deployment is a Terraform package. The customer's team reviews the plan, sees what will be created in the account, and then applies it. A proprietary installer was left out by choice: whoever is accountable for the account after everyone leaves the call needs to be able to read what went up.
Three paths tend to get collapsed into one, and separating them answers most of the network team's questions.
The company's people use the platform through the browser, over HTTPS, with the corporate identity they already use. This path never touches the vendor at any point.
The vendor operates through a connection the environment itself opens outward and keeps alive. Health metrics travel over it, along with the running version and whether the last operational task succeeded. Business records, table or document content, application logs and credentials never cross it. Because the connection originates from inside, there's no inbound port open for day-to-day operation.
A vendor person only comes in to investigate an incident, under the customer's authorization, with a named credential and a logged record. Access is revocable, and the platform keeps running after it's cut.
The first one decides it on its own in most cases. Does the data need to sit in an account the company itself owns? If yes, the path is BYOC, and the next technical conversation is about how to make that model fit.
The second: is there someone who takes care of the cloud account? If not, the hosted model is the one with no prerequisite on the customer's side.
The third: does the company have a cloud spend commitment to draw down? If yes, BYOC tends to come out ahead, because the platform's cost works against a commitment that already exists.
In BYOC, the internal cycle sets the timeline. Opening the account, granting access and approving the change are the customer's steps, and they're what decide when the environment goes up. Because the account stays the company's, a new policy or an egress block created later affects the environment.
In the hosted model, the house's own cloud policies don't apply, because the account isn't the company's, and access is through the console, never entering the cloud underneath. In both, switching regions later means rebuilding the environment.
Neither one solves the previous problem. Without a trustworthy source system, there's nothing to link into the graph, and the order between the context layer and the AI agents weighs more on the outcome than the choice of cloud account. Where the platform runs gets decided after which sources it's going to query.
Before comparing vendors on price, bring two questions: where does each of the places data is stored actually sit, and who writes the permission rule? If the answer depends on copying the database into the seller's environment, the deploy choice was made without the company in the room.
If you're putting together a security questionnaire for an AI project this quarter, reach out and I'll walk through the scope with you.
Talk to a Strattum expert about BYOC, hosted deploy and your Company Brain.