Privado por defecto: datos y credenciales en tu perímetro
Cloud GIDO is delivered as a control plane you deploy. Public demos use synthetic sample data and do not persist visitor changes. Production data, secrets, and identity remain in the customer environment unless a specific integration is agreed in writing.
In a private deployment, business data, event payloads, and risk decision context stay in the customer VPC, cluster, and stores. The public website and demo shells are separate sample environments. We do not operate a hosted production data plane for customer workloads.
How credentials are managed
Data-source tokens, infrastructure secrets, and service accounts belong in the customer-controlled secret store. Public demo credentials must not be copied into a real environment. Website lead forms only collect evaluation contact fields; they are not a path for production secrets.
Identity and RBAC
Workspace membership, roles, and least privilege are product controls to map during PoC. Upstream SSO is an integration to validate, not a default that is already live in every environment.
Audit logs
Confirm which administrative, publish, execution, and decision actions must be retained, for how long, and who can review them. Retention and alerting are agreed for the target environment.
Network exposure
Define ingress, egress, TLS termination, and which consoles or APIs are reachable from where. Demo shells on the public site are UI-only sample surfaces. Production exposure is a customer network decision recorded in the deployment boundary.
Backup and recovery ownership
Backup policy, restore drills, RPO/RTO objectives, and business-continuity decisions stay with the customer platform team. Cloud GIDO can help document retry, replay, rollback, and restore procedures in scope; we do not replace your backup product or claim a recovery SLA here.
Private-delivery responsibility model
You own cloud accounts, clusters, data, identity source, and production change approval. Cloud GIDO owns product software and the architecture, hardening, and enablement work written into the statement of work. Support process follows the selected engagement—not an unpublished blanket commitment.
This page is an evaluation boundary, not a certification, SLA, or penetration-test report. Environment-specific coverage is confirmed during architecture review and PoC.
We do not claim third-party certifications on this page. Ask for evidence that matches your compliance program during review.
Customer-owned
— Cloud account, cluster, storage, network, and data
— Identity source, credentials, backup policy, and compliance decisions
— Production change approval and business continuity objectives
Cloud GIDO scope
— Product software and agreed deployment artifacts
— Architecture, integration, hardening, and enablement work in scope
— Issue handling and response process defined by the selected engagement