Client-owned subscription

Agents deploy into the client's Azure tenant. VCG has operator access during the engagement. Access can be revoked at any time without disrupting the agent.

Tailnet isolation

Agents talk to client infrastructure over tailnet-isolated networks. No shared runtime with other clients. Compromise surface is one-agent-at-a-time, not fleet-wide.

No client data at VCG

VCG runtime infrastructure holds zero persistent client data. Logs are client-side. Memory is client-side. We see what we need to see, when we need to see it — nothing sticks.

MODEL
Opus 4.7
Anthropic · Claude
CLOUD
Azure
Client subscription
PARTNER
MS ISV
MPN 7081176
NET
Tailnet
Segmented per client

What we do, explicitly.

01 / ACCESS

Named, auditable

Each agent has a named identity in the client tenant. Every action is attributable.

02 / SECRETS

Client-held

API keys and credentials live in the client's Key Vault. VCG never mirrors them.

03 / LOGS

Client-retained

All agent action logs are written to the client's log sink. VCG keeps no copy.

04 / HANDOFF

Keys stay with you

When the engagement ends, VCG access is revoked. The agent keeps running — for you.

Security issue or disclosure?

Email Anton directly. Encrypt if you want — a PGP key is available on request. We triage within one business day.

[email protected]