Trust
Security & data handling
Azimuth runs on your infrastructure. Your code, requirements, and data never leave your environment, and the only outbound path is to the AI providers you explicitly approve. This page summarizes the controls that make that true.
The controls
What holds the boundary
On-premise by design
Azimuth installs into the environment you already run. No source code, requirements, or internal data is transmitted to or stored by Weeden Solutions.
Approved providers only
Source, requirements, and decisions are sent only to the AI providers you approve. Never anywhere else. You control where your data goes.
Human approval gates
Human approval at meaningful risk points, quality gates before merge, and ownership boundaries on what agents may create.
Full audit trail
A complete, deterministic record of what the AI did and why, drawn from your real project data with no manual entry.
Data boundary
Where your data lives
Azimuth is not a multi-tenant SaaS. The framework, its context stores, its governance reports, and its audit trail all live on infrastructure you operate. Weeden Solutions never hosts your code, tickets, requirements, logs, or decisions.
The AI tools Azimuth drives are the ones you already license and approve. Data reaches an AI provider only when your configuration authorizes that provider, and nothing is routed through Weeden Solutions on the way.
Regulated buyers can run Azimuth with zero outbound connectivity: the air-gapped deployment option keeps every byte inside your network.
SOC 2 posture
A SOC 2 readiness program is in place covering Security, Availability, Confidentiality, and Processing Integrity. Your code, activity log, and tokens are deliberately outside our audit boundary because they stay on your infrastructure.
For security questionnaires, architecture reviews, or data-flow documentation for your compliance team, contact us and we will work through your process.
Governance
Governed by design
Security review runs on every new endpoint, form handler, and auth change. Roadmap-first creation and ownership boundaries decide what agents may build. The audit trail records what the AI did and why, so your compliance team reads evidence, not assurances.