Exploded view: control plane vs data plane
YOUR VPC / NETWORK
Deployment models
BYOC
Run in your cloud account.
On-Prem
Keep control in your network.
Air-gapped
No external dependency.
Executive summary
- Control plane inside your perimeter — governance without "trust-us" routing.
- Data-plane enforcement — policy and data controls before requests reach models/tools.
- Audit evidence by default — every decision is recorded for SOC and compliance.
Next: Agents
See how Airlock governs agent runtimes, A2A interactions, and safe code execution.
View Agent Controls