

Run Backbond WhereYour Data AlreadyLives
Managed cloud, your own VPC, or entirely inside your network. The deployment changes; the platform does not.
Your formulations, your results and the model that learns from them stay yours, and are never training data for anybody else.
Three ways to run it, and one platform
The difference between them is who holds the infrastructure, not what the software can do. Nothing is held back for the managed tier, and nothing is missing from the air-gapped one.
Managed cloud
We run it, on isolated infrastructure per tenant, in the region you choose. Your workspace is up the day the agreement is signed, and nothing about the platform is shared between customers except the code.
- Single-tenant database and object storage
- Region pinned at contract time
- Customer-managed encryption keys on request
Your VPC
The whole stack runs in your cloud account, under your network policy, your identity provider and your monitoring. We ship the images and the operator; you hold the infrastructure.
- Runs in your account, your VPC, your subnets
- Egress restricted to the endpoints you allow
- Your logging, your alerting, your retention
On-premise and air-gapped
For sites where nothing leaves the building. The platform installs into your own data centre, and in the air-gapped configuration it never opens an outbound connection at all: updates arrive as signed bundles you inspect and load.
- No outbound connection required to run
- Signed release bundles, verified before load
- Bring your own models, or run ours locally
The controls a review asks for, on every tier
Single sign-on is not an upsell here, and neither is the audit log. The same controls ship with the managed cloud, your VPC and an air-gapped install, because a control that only some customers get is one nobody can rely on.
Identity and access
- Single sign-on
- SAML 2.0 and OIDC against your identity provider, with enforced SSO for the whole tenant.
- Provisioning
- SCIM for joiners and leavers, so access ends when employment does.
- Roles and projects
- Role-based access down to the project, so a contractor sees one programme and not the portfolio.
Data protection
- Encryption
- TLS 1.3 in transit, AES-256 at rest, on every deployment including on-premise.
- Key management
- Customer-managed keys, and in your own deployments your KMS never leaves your account.
- Isolation
- One tenant, one database. No shared tables, no cross-tenant queries, no exceptions.
Operations
- Audit trail
- Every read, write, run and export is logged with actor and time, and streams to your SIEM.
- Backups and recovery
- Point-in-time recovery, tested restores, and documented objectives you can hold us to.
- Change management
- Signed releases, staged rollout, and a version you choose to move to rather than one that arrives.
Assurance
- Independent testing
- Third-party penetration testing, with the report available under NDA.
- Vulnerability handling
- Dependency and image scanning in the pipeline, with defined remediation windows.
- Secure development
- Reviewed changes, least-privilege service accounts, and no standing production access.
Your science stays your science
The reason a materials or formulation team is careful about this is not abstract: the data is the company. So the guarantees below are architectural rather than contractual, and the contract says them too.
Your data is not training data
Nothing you upload, run or generate is used to train a model that anybody else can reach. Not the shared models, not another customer's workspace, not a benchmark. There is no setting to get this wrong, because there is no pipeline that does it.
The model you improve stays yours
Every result you feed back sharpens a model that belongs to your deployment. If you leave, it leaves with you as weights and artefacts you can load elsewhere, not as a service you have to keep renting.
You decide what is kept
Retention is configurable per project, deletion is real deletion rather than a hidden flag, and an export is a complete one: formulations, runs, evidence and the reasoning behind each recommendation.
Confidentiality is structural
The people who can see a customer environment are a named list, access is time-boxed and logged, and in your own deployments the answer is simpler still: we cannot see it, because we are not in it.
Build your own AI on your own science
Most vendors sell you access to their model. The point of running Backbond inside your walls is that the asset compounds on your side of the wall: your literature, your lab books, your failed runs, your process quirks.
A knowledge graph of your own
Your papers, reports and lab records become a structured, queryable model of what your organisation actually knows, including the results that were never published.
Models calibrated on your results
Predictors are fit to your measurements and your equipment, so the numbers they return are in the units your team signs off, at the tolerances your instruments give.
Agents that follow your procedures
The reasoning is configured against your SOPs, your restricted substance lists and your qualification gates, so a recommendation arrives already inside your rules.
Bring your own models
Run the models we ship, your own fine-tunes, or a model your security team has already approved. The platform is the harness, not the lock-in.
What a security review gets from us
Reviews are answered by the people who built the platform, with documents rather than adjectives.
Documentation
Architecture and data-flow diagrams, a filled security questionnaire, and the subprocessor list.
Evidence
The current penetration test report and our vulnerability management policy, under NDA.
Agreements
Data processing terms, defined breach notification windows, and support for your paper rather than only ours.
A person
A named engineer on the call, not a form. Reviews are answered by the people who built the thing.
Write to security@optagonlabs.com and an engineer will answer it, or start with a working session and we will bring the architecture with us.