InstaLILY Cloud
Managed hosting in a dedicated cloud project provisioned for your organization. Fastest to deploy.
- HostingGoogle Cloud Platform
- IsolationDedicated GCP project
- RegionsAny region, set per contract
- Operated byInstaLILY
InstaLILY deploys AI agents into the systems your business already runs on: SAP, NetSuite, Epicor, Salesforce, Snowflake. Every customer gets an isolated environment, every agent runs on a scoped identity, and every high-risk action routes to a human before it executes.
Some data cannot leave the perimeter. Rather than ask you to make an exception, we deploy where your policy already allows.
Managed hosting in a dedicated cloud project provisioned for your organization. Fastest to deploy.
Deployment inside your own cloud environment, for teams whose policy requires data to stay in their account.
For regulated or latency-bound environments, including the Small Data Center footprint.
On-site deployments run on the Small Data Center. Buyers with a regional obligation should also read European regulatory compliance.
Both reports below were issued by an independent accounting firm after testing our controls against published criteria. Full reports are available to customers and prospects under NDA.

A Type II report tests whether controls actually operated over a full year, not whether they existed on one day. The auditor reported no exceptions across every control tested.

InstaLILY operates as a business associate, not a covered entity. An independent accountant examined our compliance against the HHS HIPAA Audit Program, covering the Security and Breach Notification protocols, and found our assertion fairly stated.

Between audits, control evidence is collected continuously rather than reconstructed at year end. Policies are versioned, owned, and carry scheduled renewal dates.
Security teams evaluating InstaLILY can request the full package at hello@instalily.ai. We also complete customer security questionnaires.
InstaLILY is not ISO/IEC 27001 certified. For customers subject to GDPR, we act as a processor and execute a data processing agreement on request.
An AI agent that can write to your ERP is a privileged user. We treat it like one. Below is a real quoting action moving through the controls, the same path every action takes, whether a person is watching or not.
Agents are provisioned with dedicated service accounts under role-based access control and the principle of least privilege. Those service accounts are included in periodic access reviews alongside human accounts, so an agent's permissions are audited the same way an employee's are.
Every customer runs in a dedicated single-tenant Google Cloud project, so an agent cannot reach another customer's data by design rather than by filter. Within your tenant, agent scope is constrained to the systems and records you connect.
External data is pre-sanitized and strict data boundaries are enforced at ingestion points, to mitigate prompt injection and adversarial input. A malicious instruction buried in a supplier PDF or an inbound email is treated as data, not as a command.
High-risk and sensitive operations route to a human intervention workflow before they execute. You define which operations qualify: margin floors, discount thresholds, spend limits, and which records an agent may write to. Because every deployment is built for one business, what counts as high-risk and how an unanswered approval behaves are set during implementation rather than fixed in the product.
Agent outputs are rate limited and every action is logged, so there is a record of what the agent did, when, and on whose request.
Prompts and prompt templates are versioned in a prompt management or version control system, and the model weights we train are managed through a model registry. Any result is back-traceable and reproducible within the tolerance that non-deterministic language models allow.
One boundary around everyone. Separation is a value in a column, enforced by application logic.
A dedicated Google Cloud project each. Separation is a property of the infrastructure, the boundary the provider uses between unrelated companies.
One caveat we would rather state than bury: automated tracing can occasionally capture customer data in application logs. We scrub logs before persistence, log data is stored with defined retention and automatically removed, and this is disclosed in our SOC 2 system description.
Managed backups with point-in-time recovery, encrypted with KMS-managed keys. Infrastructure is defined as code, so an environment can be rebuilt rather than repaired.
No significant security incidents occurred in the services provided to customers during the SOC 2 observation period ending 22 February 2026.
A named Head of Security coordinates response, with severity classification, mandatory 24-hour internal reporting, and containment for critical and high incidents. Affected customers are notified directly and without undue delay, in time to support your own regulatory reporting deadlines.
Email hello@instalily.ai. You will get a response within two business days, updates at each stage of review, and credit once the issue is validated and fixed. We do not pursue legal action against good-faith research conducted within scope.
Every vendor is risk-classified, contractually bound to security requirements, and reviewed annually. We review their audit reports the same way you review ours.
| Provider | Purpose | Location | Scope |
|---|---|---|---|
| Google Cloud Platform | Primary hosting, database, storage, orchestration, WAF, secrets | Per deployment | Customer data |
| Microsoft Azure | Search indexing and supplemental processing | Per deployment | Customer data |
| Model providers | Model inference: | Per deployment | Customer data |
| Datadog | Monitoring, APM, log aggregation, alerting | United States | Log data |
| Grafana | Monitoring and observability | United States | Log data |
| Drata | Compliance monitoring and control evidence collection | United States | No customer data |
| Vercel | Frontend hosting and delivery | United States | No customer data |
| GitHub | Source control and CI/CD | United States | No customer data |
| Google Workspace | Internal identity, SSO, and MFA for InstaLILY staff | United States | No customer data |
Because the platform is model-agnostic, the inference providers in scope depend on how your deployment is configured, and the enabled set can be expanded or restricted per deployment. Retention with model providers is set by configuration to what your deployment requires, including zero retention where the provider supports it, rather than by a separately negotiated contract term.
Last reviewed February 2026. Reviewed annually and on any material change.
Everything specific to European regulation sits in one place, including what we do not hold. The two documents below are the ones a European security review asks for by name.
No cross-customer models are trained, and any use of your data for training, fine-tuning, or inference stays within your single-tenant boundary. Retention with third-party model providers is set by configuration to what your deployment requires, including zero retention where the provider supports it. We will confirm the exact providers and settings for your deployment during security review.
Only where you have decided it should. High-risk and sensitive operations route through a human intervention workflow before executing, and which operations qualify is configured during implementation rather than fixed in the product. Every agent action is logged whichever path it takes.
At the cloud project level. Each customer gets a dedicated Google Cloud project rather than a shared database with a tenant column, so isolation is a property of the infrastructure rather than of application logic.
Production data access requires approval and is granted temporarily, never standing. Access is subject to audit logging, and production data is never copied into development or test environments. Staff with authority to approve that access are in the United States. In many deployments, production data access sits on the customer side, where we neither grant nor deny it.
No significant incidents occurred during the SOC 2 observation period from 23 February 2025 to 22 February 2026, and none have occurred since. The auditor tested our incident response controls and noted no exceptions.
No, and it has not been scoped. We hold a SOC 2 Type II report covering the security criteria and an independent HIPAA attestation. If ISO 27001 is a requirement for your organization, tell us during evaluation.
Email hello@instalily.ai. We will share the current report under NDA, along with the HIPAA attestation, penetration test summary, and subprocessor list.