Customer-environment only
There is no Carbon SaaS. Intake answers and generated bundles stay inside your perimeter. Teams that cannot run software in their environment are not a fit — we would rather say that than pretend.
Carbon · Security
Carbon installs in your VPC, private cloud, or on-prem. We do not host inference. We do not mix projects. If a bundle is altered after export, the log will say so.
There is no Carbon SaaS. Intake answers and generated bundles stay inside your perimeter. Teams that cannot run software in their environment are not a fit — we would rather say that than pretend.
Wire Azure OpenAI, AWS Bedrock, GCP Vertex, or an internal model server. Carbon does not host inference. Your model contract is your model contract.
Zero cross-project context bleed. A 510(k) build cannot see a FedRAMP build. Isolation is a product rule, not a setting buried in a tenant switch.
history.log is hash-chained. Any post-export modification is detectable with one command. Counsel and auditors get provenance, not a screenshot of a wiki.
SOC 2 Type II, ISO 27001, and BAA are under active development. They are not achieved. Enterprise questionnaires will receive an incomplete answer until they are. We would rather lose a deal on honesty than win it on a badge we do not have.
Quality inside the product is already deterministic: STRIDE threat modeling, ASVS verification levels 1–3, an independent security intensity dial, RQS, EARS, and INCOSE. That is how generated content is checked. That is not the same as a company attestation.
Ask for the security questionnaire