Trust Centre / Enterprise & Deployment
Enterprise & Deployment- Options for Firms
Our Trust Centre describes the standard GoCircl service, which runs on Fly.io in the United States. That is a default, not a constraint. GoCircl is a containerized application with no exotic dependencies, and nothing about it is tied to a particular cloud provider. Enterprise clients can choose where it runs, who operates it, how users sign in, and where the AI-assisted analysis takes place.
The options below are scoped with your security and IT teams as part of an enterprise engagement, and we are happy to discuss alternatives or customization.
Three Deployment Models
Model A
Standard SaaS
Multi-tenant with logical segregation: the service available online today. GoCircl hosts and operates everything, and you receive security updates and product improvements automatically.
Suits: individuals, deal teams and firms comfortable with a hardened SaaS service.
Model B
Private Instance
A single-tenant deployment on its own isolated compute, storage and database, shared with no other client, in the region you choose. GoCircl operates it; you get isolation without running infrastructure.
Suits: firms that require tenant isolation or data-residency control, on Fly.io, AWS or Azure.
Model C
Self-Hosted
GoCircl runs inside your own cloud tenancy or network, from container images we supply. Documents, data and access remain entirely within your environment, governed by your own policies and tooling.
Suits: firms whose policies require that documents never leave their own boundary.
At a Glance
| A: Standard SaaS | B: Private Instance | C: Self-Hosted | |
|---|---|---|---|
| Tenancy | Multi-tenant, logically segregated | Single-tenant, dedicated resources | Yours alone |
| Hosting | Fly.io | Fly.io, AWS or Azure (ours, or an account you provide) | Your cloud tenancy or data centre |
| Operated by | GoCircl | GoCircl | Your IT team, with our deployment guidance |
| Region | United States | Your choice | Your choice |
| Sign-in | Email-based, with mandatory verification | Your identity provider (SAML / OIDC), or email | Your identity provider, inside your perimeter |
| AI-assisted analysis | OpenAI API, over TLS | As standard, your firm’s own OpenAI account, or an in-region endpoint such as Azure OpenAI | Your firm’s own OpenAI account or model endpoint, such as your Azure OpenAI deployment |
| Storage & encryption | Encrypted at rest; provider-managed keys | Encrypted at rest, scoped to your region; customer-managed keys by arrangement | Your storage, your keys |
| ZeptoMail | ZeptoMail, or your own mail relay | Your email infrastructure | |
| Billing | Stripe subscription | Enterprise agreement (no Stripe) | Enterprise agreement (no Stripe) |
| Logging & monitoring | Application and platform logs | Exposed per agreement, e.g. log shipping | To your SIEM, per your standards |
| GoCircl access | Named personnel, maintenance only | Named engineers under NDA, maintenance only, logged | None by default; client-initiated, time-limited credentials only |
| Updates | Automatic | Managed by GoCircl | Released to you; applied on your schedule |
What Stays the Same
The application behaves identically in every model. Whichever you choose:
- Client documents are automatically deleted within 60 minutes of processing, and are never backed up.
- Only the pages that require analysis reach the AI stage, and your documents are never used to train any model.
- The model returns text references only; every annotation is drawn and validated deterministically by GoCircl.
- Your documents and data remain your exclusive property.
The Detail
AI Stage & Data Sovereignty
For clients with data-sovereignty requirements, the AI-assisted analysis can be routed through an agreed in-region arrangement, for example Azure OpenAI in your chosen region, or a model endpoint within your own tenancy. In that configuration, document pages are analysed by a model running inside your own cloud boundary rather than by a public AI service. Any alternative model is validated against our accuracy test sets before it is relied upon.
Your Own AI Account
Private and self-hosted deployments can run the AI-assisted analysis under your firm’s own OpenAI or Azure OpenAI account rather than GoCircl’s. The AI provider is then your vendor, under your own agreement, so your data-processing terms, your retention settings (including zero data retention, where your agreement provides it) and your usage controls apply, and AI usage is billed to you directly. In a self-hosted deployment the credential never leaves your environment.
Identity & Access
Private and self-hosted deployments can integrate with your existing identity provider for single sign-on over SAML or OIDC, so access follows your own joiner-mover-leaver and multi-factor policies. In a self-hosted deployment GoCircl has no infrastructure-level access: there is no persistent or default remote access, and any support access requires your explicit initiation and time-limited credentials.
Data Residency & Backups
Private instances can be deployed in the region you require, for data sovereignty and to keep the service close to your users. Storage is scoped to that region, and operational backups (configuration and account metadata only, never documents) remain in-region.
Encryption & Audit
Customer-managed encryption keys, and write-once or cryptographically signed audit logging, are not part of the standard SaaS service but can be provided as part of a private or self-hosted deployment, using your cloud provider’s native key-management and logging services.
Self-Hosted Components
A self-hosted deployment is deliberately conventional. Resource requirements are modest and no GPU is required:
- The GoCircl web application and background worker, each supplied as a container image.
- A PostgreSQL database, and Redis for ephemeral task queues.
- S3-compatible object storage.
- Access to a model endpoint for the AI-assisted analysis stage.
Where your standards call for it, we can discuss compatible alternatives, such as cloud-native database and storage services. Network controls, certificates, backups and retention are then governed by your own policies.
Engaging With Us
Enterprise engagements are governed by our Master Enterprise Agreement, with a Data Processing Addendum covering data types, retention, security controls, sub-processors and deletion. We routinely complete firm security and onboarding questionnaires, and can share our System Security Overview, deployment and data-flow documentation, architecture diagram, policies and SOC 2 Type II report under NDA.
To discuss what your firm requires, please get in touch. For how the standard service protects your documents, return to the Trust Centre.