Data sovereignty

Your security evidence stays in your cloud. Your keys never leave your KMS.

Yeti deploys inside your cloud account. Telemetry is compressed at the edge, written to your bucket, and encrypted with keys you control. Optional model-provider and support connections follow tenant policy; a disconnected topology keeps approved services inside the boundary.

BYOC: AWS / Azure / GCP·BYOK: your KMS·Sovereign & on-prem·Disconnected option
What runs where

Evidence processing and storage run inside your account.

Collection, processing, search, and retained evidence stay where the data lives. Optional model, support, update, and connector paths are explicit, tenant-policy governed, and topology-specific.

Inside your cloud
Collection agent
Lossless compression
Object storage (your bucket)
Encryption keys (your KMS)
Chunk catalog (your ClickHouse)
Detection engine
The AI investigator
Query and retrieval
Control plane, operate only
Software configuration
Version updates
Operational health and metrics
Licensing
data access: topology-scoped
How your data is protected

Four controls, and every one of them is yours to hold.

Cloud-native identity, no shared secret

Supported cloud paths use short-lived, scoped workload identity such as IRSA, GCP Workload Identity, or Azure Managed Identity. Other topology-specific secrets and provider credentials remain explicit evaluation items.

Your keys, generated and revoked by you

Every chunk is encrypted at rest with a key you create and rotate in your own KMS. Revoke it and the archive goes dark on your command, with no support ticket and no vendor in the loop.

Encrypted end to end

Data is encrypted at rest with your KMS key and in transit with TLS. The bytes are protected from the edge where they are collected to the bucket where they come to rest.

Zero-egress option

For classified and sovereign estates, Yeti can use a disconnected topology in which telemetry, retrieval, detection, and approved model services remain inside the customer boundary.

Why it matters

Built for the buyers who cannot move their data.

Regulated buyers evaluate residency, key custody, access, evidence retention, and outbound dependencies against their own obligations. Yeti’s customer-controlled patterns can support that evaluation; the deploying organization and its assessor determine compliance.

FedRAMP
control-support mapping
IRAP
control-support mapping
HIPAA
control-support mapping
EU / Gulf
residency evaluation
Deployment model
Where your data lives
Key custody
Vendor egress
Sasquatch
Your AWS, Azure, or GCP account
Your KMS
Topology-controlled
Vendor-cloud SIEM
The vendor's cloud
Vendor-managed
All of it
Single-cloud SIEM
Your account, one cloud only
Mixed
Varies

Keep every security signal. Keep it in your cloud.

Tell us what your environment looks like and we will map the deployment to your cloud, your keys, and your residency requirements.