Security and deployment
Agree the boundary before content moves.
Studio engagements document where project content is processed, which infrastructure and model are used, who can access it, what is retained, and how the engagement closes.
Deployment posture
The promise follows the contracted architecture.
DragonKeep does not make one universal “no external server” claim across every mode. The supported path is selected and documented for the engagement.
Infrastructure
Pilots and standard licenses run on our managed cloud deployment. Customer-hosted and air-gapped configurations are the enterprise path, documented as part of scope.
Models and data flow
Name the model path and every system project content passes through. Local-model configurations can be scoped where required.
Access and retention
Agree who can access project content, what is logged, how long data is retained, and the closeout date.
Governed change
AI-assisted changes enter a reviewable ChangeSet path. They do not silently become governed canon without human review.
Questions resolved in scope.
The security discussion should produce a concrete data-flow summary and a written closeout path—not a generic badge wall.
- Hosting location and responsible operator
- Model and provider, including any subprocessors
- Network path and project isolation
- Authorized roles and support access
- Logs, backups, and retention periods
- Export format and deletion confirmation
- Incident contact and contractual controls
Plain-language commitment
Humans remain in control of canon.
DragonKeep surfaces evidence for review. Narrative owners decide whether to correct, accept, suppress, or record an exception. AI-assisted output does not become governed canon merely because a model produced it.
Bring the constraints into the first conversation.
Customer-hosted, local-model, air-gap, residency, retention, and deletion requirements belong in scope before anyone asks for project files.
Start the security conversation
