Solutions

PMO1 builds sovereign, autonomous agent ecosystems that solve your hardest business problems—securely, locally, and reliably.

PMO1 is a self-hosted AI agent platform designed for enterprise environments. PMO1 provides software only and does not host, operate, or access customer production environments or customer data. The platform is architected to enable customer compliance with enterprise security, privacy, and AI governance requirements, including SOC 2, GDPR, HIPAA (capability-based), and the EU AI Act.

PMO1 follows a defense-in-depth architecture, incorporating:

  • No direct frontend access to LLMs or external APIs
  • Centralized backend routing via a secure middleware gateway
  • Policy enforcement and inspection prior to any data egress
  • Isolation of administrative controls from operational workflows
  • Sanitized content rendering to mitigate XSS and injection risks

This architecture materially reduces data leakage, unauthorized access, and misuse risk.

Security-by-Design Architecture

Identity & Access Control

  • Built-in Role-Based Access Control (RBAC) supporting administrative, operational, and audit roles
  • Designed for integration with enterprise identity providers using SAML 2.0 / OpenID Connect (OIDC)
  • Supports least-privilege access models and separation of duties

Authentication enforcement, MFA, and user lifecycle management are controlled by the customer’s identity provider.

  • PMO1 does not collect or process customer data outside customer environments
  • Supports privacy-by-design principles, including data minimization and pre-processing controls
  • Includes mechanisms to detect and redact sensitive data prior to external API calls
  • Enables customer-controlled data deletion and retention policies

Customers remain the data controller and are responsible for lawful processing decisions.

Data Protection & Privacy

Regulatory Alignment

  • SOC 2: Secure software development practices and audit-ready control design
  • GDPR: Supports customer compliance through access control, deletion mechanisms, and data minimization
  • HIPAA: HIPAA-capable when deployed in compliant customer environments; PMO1 does not act as a Business Associate
  • EU AI Act: Provides logging, traceability, human oversight, and deployment guidance aligned with provider obligations

Operational compliance obligations are fulfilled by customers based on deployment context.

  • PMO1 follows a clear Shared Responsibility Model:

  • PMO1: Secure architecture, governance capabilities, documentation, and compliance enablement
  • Customer: Infrastructure security, identity enforcement, encryption, monitoring, and regulatory execution

Shared Responsibility Model

Note: PMO1 provides a self-hosted software platform and does not operate customer environments or process customer data. Actual security controls, compliance obligations, and regulatory outcomes depend on customer deployment, configuration, and operational practices. No representations or warranties are made regarding compliance with any specific law, regulation, or standard.

FAQs

Does PMO1 host or operate customer environments? arrow faq
No. PMO1 provides a self-hosted software platform deployed and operated entirely within the customer’s environment. PMO1 does not host, operate, monitor, or access customer production systems or customer data.
Does PMO1 access customer data? arrow faq
No. PMO1 does not access customer data in self-hosted deployments. All data ingestion, processing, storage, and deletion occur within customer-controlled infrastructure.
Is PMO1 a data processor or controller under GDPR? arrow faq
In self-hosted deployments, PMO1 acts as a software vendor, not a data controller or data processor. Customers determine purposes and means of processing and remain the data controller. PMO1 provides technical mechanisms to support GDPR compliance, including access controls, audit logging, and deletion capabilities.
How is access controlled within the platform? arrow faq
PMO1 implements a role-based access control (RBAC) model supporting administrative, operational, and audit roles. The system enforces least-privilege access through role-scoped permissions.
How does PMO1 prevent unauthorized access to external services or LLMs? arrow faq
The platform uses a middleware gateway pattern, ensuring: No direct frontend access to LLMs or external APIs All requests routed through a centralized backend gateway Policy enforcement, logging, and inspection prior to data egress This design significantly reduces data leakage risk.

Solutions