Our cloud, or the full data plane in yours.

Run RegWatch in our cloud, or run the full data plane in your own cloud account with Private VPC: AWS, Microsoft Azure, Google Cloud, IBM Cloud, Oracle Cloud or another provider. Buy directly, through AWS Marketplace or through Azure Marketplace.

RegWatch cloud

We run and update the platform. Your data is isolated from every other tenant in the database.

RegWatch cloudApplication and agentsPostgres with row-level security

Private VPC

The full data plane runs in your own cloud account: AWS, Microsoft Azure, Google Cloud, IBM Cloud, Oracle Cloud or another provider.

Your cloud accountApplication and agentsDatabase and documents

Your policies and contracts may not leave your cloud.

Internal policies, contracts and evidence are among the most sensitive files a regulated firm holds. Many security teams will not approve a new vendor cloud for them, and a new vendor still needs a way through procurement.

  • Security questionnaires ask where data is processed and who can reach it.
  • Some content may not leave the firm’s own cloud account.
  • Every new vendor needs a contract route procurement already trusts.

Set up the workspace

The onboarding agent drafts your company profile and suggests jurisdictions, topics and sources. Your administrators invite the team and assign roles.

Set up the workspace
Set up the workspace

Agents run where the data lives

In Private VPC, the application, agents, database and documents run in your own cloud account, and the agents call the model providers with API keys you supply.

Agents run where the data lives
Agents run where the data lives

Changes on record

In either deployment, changes are written to a tamper-evident, append-only audit log, with the actor, the action and the reason.

Changes on record
Changes on record

What you get

  • RegWatch cloud

    We run and update the platform. Your data is isolated from every other tenant in the database with Postgres row-level security.

  • Private VPC

    The full data plane runs in your own cloud account, with your own database, cache and storage: AWS, Microsoft Azure, Google Cloud, IBM Cloud, Oracle Cloud or another provider.

  • Your model-provider keys

    A Private VPC deployment calls the model providers with API keys you supply, under your own agreements with them.

  • Network access you control

    Private VPC only reaches the model providers and the regulatory sources your watchlists read. Optional features such as email add their own destinations to your allow-list.

  • One application in both

    The same application runs in our cloud and in your account: watchlists, alerts, obligations, evidence, reports and RegWatch Legal.

  • Single sign-on and roles

    SAML and OIDC single sign-on, and role-based access with 9 roles, with RegWatch Compliance and RegWatch Legal access granted separately.

  • Bought the way you buy

    Buy directly, through AWS Marketplace or through Azure Marketplace. Private VPC for RegWatch Compliance and for RegWatch Legal has public AWS Marketplace listings.

Questions

What do we run in our account for Private VPC?

A Kubernetes cluster for the application and agents, a PostgreSQL database, a Redis cache and object storage, installed from a Helm chart. On AWS that means Amazon EKS and S3; other clouds use their own equivalents. You supply the model-provider API keys, and backups and TLS stay under your control.

Does Private VPC need internet access?

Only outbound, to the model providers and to the regulatory sources your watchlists read, plus optional features such as email. The application, database and documents stay in your account.

What does Private VPC cost?

It is part of Enterprise and quoted for your deployment. The infrastructure runs in your own cloud account, so your cloud provider bills it to you.

Where does our data live?

In RegWatch’s cloud, or in your own cloud account with Private VPC: AWS, Microsoft Azure, Google Cloud, IBM Cloud, Oracle Cloud or another provider. Tenant isolation is enforced in the database with Postgres row-level security, and customer content is not used to train generalized AI models by default.

See RegWatch in the deployment you need.

Tell us whether you are reviewing our cloud or Private VPC when you book.

Book a demo