Sciensa | Tessera

// Téssera · Deployment & Security

Your data stays inside your perimeter. AI runs the way compliance allows.

Three deployment modes, data residency by construction, and secrets managed by Tessera. Not by accident. By architecture.

// WHERE IT RUNS

Three deployment modes. You choose where AI operates.

Tessera Cloud for teams who want to move fast. Isolated Cloud for those who need a dedicated tenant. BYOC for those who require everything inside their own environment.

Same runtime · same governance · deployment choice based on risk and architecture

Cloud Tessera

Tessera Cloud

Accelerated go-live for teams that need speed, with data isolation by design.

Multi-tenant
Managed operations
Fast go-live
VPC Privada

Isolated Cloud

Private VPC and dedicated tenant. Your data never shares an environment with other clients.

Dedicated tenant
Private VPC
Restricted traffic
BYOC

BYOC

Bring Your Own Cloud. Tessera runs entirely inside your infrastructure. Nothing leaves.

Inside your environment
Nothing leaves
Full control

The same runtime layer, policies, and observability in any deployment model.

Diagrama: Dados no Perímetro

// DATA INSIDE THE PERIMETER

The data doesn't leave. That's not a setting. It's architecture.

Tessera's data model was designed to protect what matters most: the sensitive content of your institution.

Everything happens inside your environment. No data flows through external systems without explicit, controlled instruction.

For regulated institutions, the architecture meets BACEN 4.658 data residency requirements and LGPD guidelines.

Processing inside your environment

Data, context, and inferences remain under your custody.

No external integration by default

External APIs and services blocked unless you explicitly authorize.

Governance and traceability

You define policies, access, and audit logs end to end.

BACEN 4.658LGPDData Residency

By construction. Not by configuration.

// SECRETS PROTECTED

API keys, tokens, and credentials under Tessera's custody.

No secret is exposed in code, environment variables, or prompts. Tessera manages the full credential lifecycle so agents operate securely, without direct contact with the raw key.

Rotation, revocation, and usage stay under policy and audit. The agent gets access to the right resource, at the right time, with a full audit trail.

Automatic credential rotation

Agent accesses the resource, not the key

Immediate revocation on incident

Log of every use and every policy applied

Secret protected by architecture, not by convention.

Diagrama: Segredos Protegidos no Vault

The agent uses the resource. The key stays protected in the Vault.

// READINESS ASSESSMENT

Let's choose together the right deployment mode for your operation.

01Map the data perimeter
02Define the deployment mode
03Configure and go live