Customer VPC deployment
QuietNode runs inside your environment. Product state and connector credentials remain under your control.
QuietNode deploys in your VPC, binds access to each teammate's role, and attaches evidence to every run. This page gives a security reviewer what they need to evaluate the platform — architecture, access lifecycle, controls, and what the audit trail actually looks like.
100% golden-eval accuracy
121/121 golden cases passing, zero grounding violations — enforced in CI
Read-only by construction
SELECT-only access unless a write path is explicitly configured
Deployed in your VPC
Product state and connector credentials stay under your control
QuietNode runs inside your VPC, with product state and connector credentials under your control. Investigations and change preparation use scoped connectors in your environment. Prompt and model traffic follows the endpoint you configure, including a private in-VPC endpoint when required.
Business question or ticket
Slack, chat, or Jira intake
QuietNode platform
Runs inside your environment
Scoped connectors
Warehouse — read-only
SELECT-only sessions, allowlisted schemas
BI tools
Report metadata, lineage, refresh state
Git
Branch and pull request only
Evidence + approval gate
Evidence pack assembled; nothing moves without sign-off
Human reviewer
Your team approves the outcome
Pumpkin receives a short-lived, least-privilege STS session after approval, and that session expires when the run ends. QuietLens uses a customer-managed, read-only service identity constrained to approved sources. Both paths leave an audit record.
Request
An approved ticket opens a Pumpkin run
Scope bound to task
Repository and environment fixed up front
Short-lived credential issued
STS session, least privilege, expiry set
Run executes
Change prepared in the approved environment
Credential expires
Session ends at TTL — no standing access
Audit record
Scope, queries, approvals, outputs retained
These are not configuration options layered on afterwards — they are how the platform executes work. Every Pumpkin task and every QuietLens investigation runs through the same eight controls.
QuietNode runs inside your environment. Product state and connector credentials remain under your control.
Database access is read-only by default — SELECT-only unless a write path is explicitly configured.
Pumpkin uses short-lived sessions; QuietLens uses a customer-managed read-only identity. Secrets are never stored in plain text.
Capabilities are bound by role, so each AI teammate can only reach what its scope allows.
Every code or production change waits for an assigned reviewer to approve before it moves.
Chats, connector actions, queries, and PRs are recorded end-to-end for every run.
Nothing reaches production on its own. Pumpkin prepares the change and waits for human review.
You control the LLM and data routing mode — choose how prompts and data move through the platform.
An illustrative run shape: a business user asks why the daily revenue report is missing. It shows the trail a run leaves behind — scope, access, queries, evidence, approval, and the recorded action.
Illustrative audit timeline
Run QN-2189 — missing daily revenue report
06:42:10 UTC
Scope bound
scope: revenue_dailyInvestigation bound to the revenue_daily report lineage. Connectors in scope: Snowflake (read-only), Airflow, Power BI.
06:42:11 UTC
Read-only access checked
service identitySELECT-onlyCustomer-managed service identity checked against the allowlisted SELECT-only scope. No write grant issued.
06:43:27 UTC
Queries executed
SELECT-only4 queriesFour queries against allowlisted schemas, each logged with full query text, duration, and row counts.
06:44:05 UTC
Evidence pack attached
6 artifactsLineage trace, the failed Airflow task load_revenue_daily, last successful run, affected reports, and the owning team.
06:57:11 UTC
Investigation completed
session closedThe connector session closed. The read-only service identity remains customer-managed, with no run-specific grant left open.
07:12:45 UTC
Reviewer approved
approval: on-callData platform on-call reviewed the evidence pack and approved the recommended action.
07:13:02 UTC
Action recorded
DATA-512Operational ticket DATA-512 raised with the evidence pack attached. The full timeline is retained for audit.
Every run — execution or investigation — produces this timeline. It is retained end-to-end and exportable for your security and compliance reviews.
The questions security reviewers ask first. For anything deeper, the docs pack covers the full model.
Every run binds to approved repositories, semantic metrics, and short-lived credentials before any work starts. Out-of-scope requests are rejected with a readable reason instead of silently broadening access.
The pack itemizes the compliance control matrix, data-handling and retention policy, DPA template, eval methodology, and release provenance — plus Pumpkin’s access-control model and SOC 2 readiness map. See the full list, then request what your review needs.