Security and access
Can Arrio run in our own cloud?
The short answer
Yes. Arrio supports running in the customer’s own cloud, and it is model-agnostic: you can bring your own model and your own key. You choose where your data lives. Which arrangement is right depends on your requirements rather than on a default we impose.
Your own cloud is a supported model
For organisations whose policy is that analysis of their code happens inside their own boundary, Arrio can run there. This is one of several supported security and deployment models rather than a special case negotiated once.
It is worth being straight about why this matters more than it used to: an organisation adopting AI across engineering is being asked to send its most sensitive asset somewhere, repeatedly, by many vendors. Having a defensible answer for each one is now part of the job.
Model-agnostic, including your own
Arrio is not tied to a single model provider. It supports multiple providers, and it supports bringing your own model and your own key, including a self-hosted endpoint where you have one. If your organisation has already made a decision about which models may see your code, Arrio fits that decision rather than asking you to revisit it.
You choose where your data lives
Data residency is a choice you make, not a default you inherit. Because the exact set of regions and options changes as the product develops, the current position lives in the documentation rather than here, where a stale claim would be worse than no claim.
What stays true in every setup
Repository access is read-only. The analysis is of the work rather than of individuals. And the reading is independent, because Arrio does not sell the tools it measures.
Bring your cloud, your model and your key. The reading is the same.

