The easy way to build AI systems for clients is to put every client on one shared stack and send everything through outside services. Robby Prochnow built Zen Aegis the other way.
His rule is that nothing about a client's prompts, outputs, credentials or content leaves the boundary. Each client is isolated at the infrastructure layer, with its own host, its own secrets vault, its own tracing and its own set of tool servers. Inside the database, AI agents are treated as principals with their own permissions, and explicit deny rules make the decision log and signed agreements impossible to edit after the fact.
It means the answer to a client's security team is short. In July 2026 he wrote it down as a memo Common Ground hands to client security reviewers: three layers of fail-closed tenant isolation, how secrets are handled, what the AI layer is allowed to touch, and a receipt for every action. The posture line in it is plain: it deploys inside your tenant, and nothing leaves your environment.