Enterprise & Security

Built for firms with strict data-governance requirements.

Run VitruAI on your terms — in your environment, on your choice of models, against your security policies, backed by an SLA. For confidential or regulated work, your data never has to leave your infrastructure.

Talk to us about Enterprise

Deployment

Deploy VitruAI your way.

From the managed cloud to a fully sovereign install — you choose where your data lives.

Dedicated cloud

A single-tenant instance isolated to your firm, with region selection (e.g. EU) so your data resides where your policies require.

On-premise & sovereign

Deploy into your own datacentre or VPC. Your model data and reports stay entirely within your infrastructure — nothing leaves your network.

Managed cloud + BYOK

Stay on our hosted product but route inference through your own model key, so calls run under your provider account and terms.

Data handling

Your model stays where it belongs.

VitruAI reads your model where you authorise it and sends out only what a check needs — not your project file.

Your .rvt never leaves your machine

The add-in reads the open model locally through the Revit API. There is no project-file upload.

Only structured findings leave

Element IDs, parameter values, measurements and — where a rule needs visual evidence — rendered sheet images. Model access is strictly read-only.

Sovereign = nothing leaves

In an on-premise deployment, even that structured data stays inside your environment. You can review the full data-flow inventory at any time.

Models

Run any model — or your own.

Your choice of model

Claude by default, with the freedom to switch to OpenAI, Google Gemini, Kimi and others — or run self-hosted open models (e.g. Llama, Kimi, Nemotron) so inference never touches a third party. No single-vendor lock-in.

Never used to train AI

The providers we run commit, for business/API use, not to train on the content you send — Anthropic: “Anthropic may not train models on Customer Content from Services.” OpenAI and Google Gemini make the same commitment for paid/API use. With self-hosted models, nothing reaches a third party at all.

Security & compliance

Ready for your security review.

SSO / SAML

Connect your identity provider; provision and de-provision with your directory.

Isolation & encryption

Strict per-firm tenant isolation, encryption in transit, and encrypted backups.

Audit & residency

Audit logs and a data-residency commitment per region, with a versioned record of every QA run.

DPA & Trust Center

Signed DPA, published sub-processor list, and a data-flow inventory. SOC 2 in progress.

Request our Trust Center pack →

Support

Backed by an SLA.

1-hour P1 response

Priority-one issues get a response within the hour.

99.9% uptime

Backed by a contractual uptime commitment.

Named CSM

A dedicated customer success manager for your account.

FAQ

Questions from security reviews.

Does our model data leave our environment?

Your .rvt never leaves your machine. On the hosted product, only structured findings and (where a rule needs it) rendered images are sent for checking. In an on-premise / sovereign deployment, nothing leaves your infrastructure at all.

Is our data used to train AI models?

No. The model providers we run do not train on business/API content, and self-hosted open models keep everything in your environment. The specifics are in our security posture and Trust Center pack.

Can we run fully on-premise, with no third-party model?

Yes — a sovereign deployment on your own servers, running self-hosted open models. “Local” here means your server or VPC, not each workstation. We scope the deployment with your team.

Which models can we use?

Claude by default; switch to OpenAI, Google Gemini, Kimi, or self-hosted open models. You can also bring your own model key.

Do you have a DPA and SOC 2?

A signed DPA is available, along with a sub-processor list and data-flow inventory in our Trust Center pack. SOC 2 is in progress; request the pack for current status.

Who is accountable for the AI's output?

The architect or engineer of record. VitruAI is decision-support — it flags, explains, and recommends; the licensed professional reviews and signs off.

Book a demo

See it on your model — and we’ll set up your rule package.

We’ll showcase VitruAI, run a QA pass on a model you share, learn your firm’s requirements, and stand up your first rules.

Prefer email? Send us the details and we’ll reply within one working day.

No marketing automation list. We reply by hand within one working day.