Security and operations

Deployed where you need it.

Three levels. Same product. You choose how much you want to run yourselves.

Where does your data end up?

Your documents are plain text files in Git. Everything else Colleag keeps is built around them, so the question has three parts.

The files

Documents and original files in a Git repository. Readable without Colleag, and always yours.

The database

The search index, the history of who asked and approved what, and changes waiting for approval.

The model calls

The language model that writes the answers and the embedding model that makes text searchable.

Deployed where you need it

Start in SaaS, move into your Azure, or run on a local server. Security principles follow the option you pick.

SaaS

We operate Colleag.ai in our Azure environment in Sweden. You use the latest LLMs through us.

  • Operated in our Azure environment in Sweden
  • Latest LLMs through us
  • Search via Azure OpenAI within the EU
  • Login and backup included

For this option

Your data. Your decisions.

You own the content. We run the platform and delete data when you ask us to.

No model training

Your product data is not used to train or fine-tune models.

Access you control

You decide who gets in. Every sign-in is logged.

Full change history

Who changed what, and why. Ready when you need to show how the work was done.

More detail for IT
Where it runs

Colleag's Azure environment in Sweden (Sweden Central). The application runs in Azure Container Apps, the database is Azure Database for PostgreSQL, and secrets live in Azure Key Vault.

Isolation between customers

Every row in the database carries its organisation's id, and the API takes the organisation from the signed sign-in token — never from anything a user can edit in an address bar. A request aimed at another organisation's resource answers that it does not exist, which also does not confirm that it does.

Encryption

TLS in transit. Stored ERP and Git credentials are encrypted with Fernet (AES-128-CBC with HMAC-SHA256) and the key lives in Key Vault, not in the code. Disks are encrypted by Azure.

Sign-in and access

Microsoft Entra External ID. You invite your users and set their role; external stakeholders can be invited with access only to what has been marked customer-visible. Every sign-in is logged.

Backups and logs

The database is backed up automatically with 35 days of history. Operational logs are kept for 30 days. You own the content and we delete it when you ask.

Your ERP

Connecting an ERP behind a firewall uses an outbound tunnel you start yourself. No inbound firewall rule, no port forward, no VPN. Colleag reads; it never writes back.

The language model

Questions, and the document extracts needed to answer them, go to Anthropic. Your data is not used to train or fine-tune models.

What we do not have

We are not ISO 27001 or SOC 2 certified. We will gladly describe how the system is built, but we have no audit certificate to show. If you need a data processing agreement, we sign one.

Read in the manual →

In your Azure

The platform runs in your subscription. You connect the LLMs you want to use.

  • Your Azure subscription
  • Any LLM you choose
  • Your Entra ID
  • Your network rules

For this option

Your data. Your decisions.

Data stays in your tenant. You control storage, backup, and deletion.

Your models

Connect the LLMs you approve. Switch them when you want.

Encryption you control

TLS in transit, AES at rest. Your own keys if you want them.

Access through your directory

Your Entra ID and your network policies. Full visibility of who does what.

More detail for IT
What gets installed

One resource group in your subscription holding the application, PostgreSQL, Key Vault and storage. Colleag gets a scoped role on that resource group to install and update it — nothing else in your tenant.

Your secrets are born with you

Database password, encryption key, session secrets and ERP credentials are created in your vault at install time and have never existed at Colleag. The only Colleag-owned material in the environment is our GitHub identity, which lets the platform read and write in your repositories.

Your documents, your files

The content is ordinary Markdown and YAML files in your own GitHub organisation. Stop using Colleag and you are left with a readable archive, not an export problem.

Your models

Wire in Azure OpenAI in your own subscription and neither prompts nor answers leave your tenant. Change model whenever you like.

Your sign-in, your network rules

Your Entra ID, your conditional access, your MFA. The network rules are yours — private endpoints included, if that is what you want.

Who can see the content

Your users, by role. Colleag holds an operations role on the resource group, not on the content, and no other customer's installation shares anything with yours.

Read in the manual →

Local server

Colleag.ai runs on your hardware, behind your firewall. Also without an external connection.

  • Your hardware
  • Your network
  • Air-gapped option
  • Full physical control

For this option

Your data. Your decisions.

Nothing leaves the building. You own the servers, backups, and keys.

Models on your side

The models you connect run on your network.

Physical control

You decide who reaches the room and the machines.

Local access

Your accounts or your existing directory. Everything stays behind your firewall.

More detail for IT
What runs on your side

The whole platform on your hardware: application, database, search index and a self-hosted Git service. No GitHub app, no Colleag secrets in the environment.

Without connectivity

It can run fully disconnected. Updates then arrive on media you bring in yourself, and the language models are the ones you run locally.

What it asks of you

You own the servers, the backups, the keys and the updates. We cannot reach the environment, so support goes through you rather than through a login on our side.

Models

Local models on your hardware, or your own API account if you allow outbound traffic. The choice is yours and it can change.

Who can see the content

Only you. Colleag has no access at all to a local installation.

Read in the manual →

Which option fits you?

Four questions give a first direction for the conversation with your security lead. The suggestion is marked among the cards above and in the table below.

Does the product contain security-classified or export-controlled information?
May product data be stored with an external cloud provider?
May data be processed by an AI service in the US?
Do you have an Azure subscription of your own?

Suggestion

SaaS

The fastest start. You can move to your own Azure later without converting anything.

Where everything goes

Read the table from left to right: the further right, the less leaves your network and the more you run yourselves. Click an option to mark it.

Part
The filesDocuments and originalsColleag's Git service, or your GitHub organisationYour GitHub organisationSelf-hosted Git on your side
The databaseIndex, history, pending changesColleag's PostgreSQL in SwedenPostgreSQL in your subscriptionPostgreSQL on your side
The model callsLanguage model and embedding modelAnthropic, and Azure OpenAI within the EU for searchYour models, e.g. Azure OpenAI in your subscriptionLocal models, or your own API account
Sign-inWho gets inColleag's Entra External IDYour Entra IDYour directory
OperationsWho applies updatesColleagColleag, with a scoped role on one resource groupYou

The ERP behind your firewall

A small connector on your network dials out to Colleag, so no inbound port has to be opened. In Monitor, the company decides what Colleag can see.

How the traffic runs

MonitorYour server, unchanged
internal network
ConnectorSmall server on your network
outbound HTTPS, port 443
ColleagSaaS or your Azure
  • Colleag only reads. Nothing is written back to the ERP.
  • No inbound firewall rule, no port forwarding and no VPN.
  • Data is read when someone asks. What is kept is a search mirror of the article register and what the answers said.
  • Revoke the connector in Colleag and the tunnel closes at once.

On a local server, Colleag reaches Monitor directly, without a connector.

Limit what Colleag sees with Monitor companies

Colleag is connected to one company number at a time. Give Colleag's Monitor user access to that company only, and Monitor enforces the boundary itself.

Monitor serverExample

001.1Defence productsNo access
002.1Civil productsColleag reads here
900.1Test companyPossible for a pilot
Read about limiting by company

Combining the options

Your documents are plain files in Git in all three options. Moving between them means moving the repository, and the search index is rebuilt in the new place.

Step by step

Start in SaaS with a non-sensitive product, move to your own Azure when IT wants everything in the company's cloud, and put protected products on a local server.

Side by side

Civil products in SaaS or your Azure, protected and export-controlled products on a local server. Two installations with their own users, database and index, and no connection between them.

Who can see your data

The same three levels apply in every deployment. We would rather write them out than let an IT manager guess.

Your users

Their role decides what a signed-in person reaches: read, write, administer. External participants can be invited as stakeholders with access only to what has been marked customer-visible. Every sign-in is logged.

Other customers: never

Data is separated per organisation in every database query and every file path. A connector to your ERP is bound to your organisation and its own port, and cannot be reached from any other account.

Colleag

In SaaS, operations staff have technical access to the platform in order to run it, through Azure and with a traceable sign-in. In your Azure we hold a scoped role on the resource group and no access to the content. On a local server we have no access at all.

The language model

What you ask, and the document extracts needed to answer it, go to the model the deployment uses. In SaaS that is Anthropic, and your data is not used for training. In the other two you choose the provider yourself, or run the model locally.

Your ERP data is not stored as a copy. The exception is a search mirror of the article register — number, description, unit, status, type — which exists so product search can find an article without calling the ERP on every keystroke, and which is emptied when the integration is disconnected.

The details live in the manual: deployment options, data security and how the ERP is connected. Read the manual

Want to see which setup fits you?

Book a short meeting. We walk through SaaS, your Azure, or local operations against your security needs.

Book a meeting