Where an agent's data lives: an AWS region, your account or your server
Three ways to place an agent — and what happens to its conversations, memory, keys and model requests in each case.
What counts as an agent’s data
When people say “the agent’s data”, they usually mean the conversations. In fact there are five kinds, and they live in different places:
- conversations — the text of people’s messages and the agent’s answers;
- memory — the agent’s notes about the work and the people that will be useful in later conversations;
- secrets — the bot token and the model inputs: subscriptions and keys;
- logs and backups — service records of how the environment works, and its copies;
- model requests — what goes to the model provider on each turn: the question and the relevant part of memory.
The first four are stored where the agent’s environment runs. The fifth is processed by the model provider you chose.
Option 1. An environment in AWS, in the region you choose
The agents’ environment is set up in the AWS region where your people work and where the rules of your country require it. Everything is described in Terraform code and deploys the same way in any region.
- Each customer has its own environment — its own machine, secrets, logs and backups. Data of different customers does not mix.
- No inbound connections. Management goes through AWS Systems Manager, questions from the cabinet through a queue.
- Secrets are write-only. Tokens and keys are kept in AWS Secrets Manager, separately for each organisation. Once saved, nobody sees them, and they never reach the agent’s memory.
- Backups are encrypted. Backups are encrypted with AWS KMS keys and verified by a restore every day.
The cabinet runs separately from the environment — in the EU, in Frankfurt. It keeps what you see in the cabinet: agent cards, spend and the web chat history.
Option 2. An environment in your own AWS account
The same environment can run in your own AWS account. The bill for infrastructure and the model comes to you, and the hub’s access goes through a role that you grant and can revoke.
The model can run in the same account too: the agent calls Claude models in Amazon Bedrock through a role, and your AWS bill pays for them. With the EU-only profile, processing stays within the European Union.
Option 3. Data on your own server
If the agent’s conversations, memory and files must not leave your infrastructure, they can be kept only on your server. This is set up on request: in the agent card in the cabinet, in the “Keep data on your own server” section, or through the form on the site. We get in touch and discuss how to connect your server.
Where a model request goes
Wherever the environment runs, on each turn the question and the relevant part of memory go to the model provider and are processed on its terms:
- a Claude subscription or an Anthropic API key — at Anthropic;
- a ChatGPT subscription — at OpenAI;
- other providers — in their own jurisdictions: DeepSeek in China, GLM and Kimi in Singapore, MiniMax in the USA; for Qwen the region depends on the endpoint;
- Amazon Bedrock in your AWS — in the chosen profile; with the EU-only profile — within the European Union.
You choose the provider, and you can change it without touching the agent’s environment.
What suits what
| If what matters is | What provides it |
|---|---|
| Starting fast, with data in the right region | An environment in AWS in the region you choose |
| The bill and control with your own team | An environment in your own AWS account |
| Data that never leaves your infrastructure | Storage on your server, on request |
| Model processing in the EU only | Amazon Bedrock with the EU-only profile |
How long it is kept and what happens when you leave
The full text of conversations is kept for 30 days after the last message, the web chat history for 90 days, the agent’s notes for as long as you use the agent, and backups for 35 days.
When you leave, we hand over an export and delete the environment together with the data. Backups expire on their own within 35 days, and the encryption key is destroyed after 30 days. All retention periods and everyone who takes part in processing are listed on the Trust page.