CUSTOMER

Azimuth Data Flow

Version 1.0 — 21 August 2026

Scope: every path customer data takes through Azimuth, and every boundary it crosses. Companion to Azimuth Cloud Security Posture (platform controls), Azimuth Data Governance (lifecycle and classification) and the Azimuth Subprocessor Register (who each third party is).

A data-flow diagram is the artifact security reviewers ask for first and receive least often, usually because vendors would rather describe their architecture than draw where the data actually goes. This one is drawn at the resolution the question deserves: trust boundaries and the controls on them.


1. The diagram

<svg viewBox="0 0 860 520" xmlns="http://www.w3.org/2000/svg" role="img" aria-label="Azimuth data flow: browser to Cloudflare to the Azimuth application, which reads and writes an encrypted database and encrypted backups inside Azimuth-controlled infrastructure, and calls model providers server-side outside it." style="width:100%;height:auto;max-width:860px;background:#171310;border:1px solid #372F26;border-radius:12px"> <defs> <marker id="ar" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"> <path d="M 0 0 L 10 5 L 0 10 z" fill="#A79C8E"/> </marker> <marker id="are" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"> <path d="M 0 0 L 10 5 L 0 10 z" fill="#F65A1A"/> </marker> </defs> <rect x="400" y="26" width="300" height="468" rx="14" fill="none" stroke="#4A3D2E" stroke-width="1.5" stroke-dasharray="6 5"/> <text x="550" y="48" text-anchor="middle" fill="#A79C8E" font-family="monospace" font-size="10.5" letter-spacing="1.4">AZIMUTH-CONTROLLED</text> <rect x="30" y="222" width="140" height="66" rx="10" fill="#1F1A15" stroke="#372F26"/> <text x="100" y="250" text-anchor="middle" fill="#EDE6DC" font-family="sans-serif" font-size="13" font-weight="600">Your browser</text> <text x="100" y="268" text-anchor="middle" fill="#A79C8E" font-family="sans-serif" font-size="11">your people</text> <rect x="214" y="222" width="150" height="66" rx="10" fill="#1F1A15" stroke="#372F26"/> <text x="289" y="250" text-anchor="middle" fill="#EDE6DC" font-family="sans-serif" font-size="13" font-weight="600">Cloudflare</text> <text x="289" y="268" text-anchor="middle" fill="#A79C8E" font-family="sans-serif" font-size="11">edge · DDoS · WAF</text> <rect x="420" y="218" width="260" height="74" rx="10" fill="#241E18" stroke="#F65A1A" stroke-width="1.5"/> <text x="550" y="246" text-anchor="middle" fill="#EDE6DC" font-family="sans-serif" font-size="13.5" font-weight="700">Azimuth application</text> <text x="550" y="264" text-anchor="middle" fill="#A79C8E" font-family="sans-serif" font-size="11">all AI calls made here, server-side</text> <text x="550" y="280" text-anchor="middle" fill="#A79C8E" font-family="sans-serif" font-size="11">every read and write scoped to your org</text> <rect x="420" y="92" width="260" height="62" rx="10" fill="#1F1A15" stroke="#372F26"/> <text x="550" y="118" text-anchor="middle" fill="#EDE6DC" font-family="sans-serif" font-size="13" font-weight="600">Database</text> <text x="550" y="136" text-anchor="middle" fill="#A79C8E" font-family="sans-serif" font-size="11">encrypted at rest · not publicly reachable</text> <rect x="420" y="368" width="260" height="62" rx="10" fill="#1F1A15" stroke="#372F26"/> <text x="550" y="394" text-anchor="middle" fill="#EDE6DC" font-family="sans-serif" font-size="13" font-weight="600">Encrypted backups</text> <text x="550" y="412" text-anchor="middle" fill="#A79C8E" font-family="sans-serif" font-size="11">separate storage · expire at 35 days</text> <rect x="712" y="176" width="132" height="158" rx="10" fill="#1F1A15" stroke="#372F26"/> <text x="778" y="199" text-anchor="middle" fill="#EDE6DC" font-family="sans-serif" font-size="12.5" font-weight="600">Model providers</text> <line x1="726" y1="210" x2="830" y2="210" stroke="#372F26"/> <text x="778" y="230" text-anchor="middle" fill="#A79C8E" font-family="sans-serif" font-size="11">Anthropic · text</text> <text x="778" y="252" text-anchor="middle" fill="#A79C8E" font-family="sans-serif" font-size="11">Lightricks · video</text> <text x="778" y="274" text-anchor="middle" fill="#A79C8E" font-family="sans-serif" font-size="11">LiveKit · voice</text> <text x="778" y="302" text-anchor="middle" fill="#46B981" font-family="sans-serif" font-size="10.5">contractually barred</text> <text x="778" y="317" text-anchor="middle" fill="#46B981" font-family="sans-serif" font-size="10.5">from training</text> <line x1="172" y1="255" x2="208" y2="255" stroke="#A79C8E" stroke-width="1.5" marker-end="url(#ar)"/> <text x="190" y="243" text-anchor="middle" fill="#A79C8E" font-family="monospace" font-size="9.5">TLS</text> <line x1="366" y1="255" x2="414" y2="255" stroke="#F65A1A" stroke-width="1.5" marker-end="url(#are)"/> <text x="390" y="243" text-anchor="middle" fill="#F65A1A" font-family="monospace" font-size="9.5">TLS</text> <text x="390" y="278" text-anchor="middle" fill="#F65A1A" font-family="monospace" font-size="9">CF ONLY</text> <line x1="550" y1="214" x2="550" y2="160" stroke="#A79C8E" stroke-width="1.5" marker-end="url(#ar)" marker-start="url(#ar)"/> <text x="562" y="188" fill="#A79C8E" font-family="monospace" font-size="9.5">TLS enforced</text> <line x1="550" y1="296" x2="550" y2="362" stroke="#A79C8E" stroke-width="1.5" marker-end="url(#ar)"/> <text x="562" y="334" fill="#A79C8E" font-family="monospace" font-size="9.5">every 6 hours</text> <line x1="684" y1="255" x2="708" y2="255" stroke="#A79C8E" stroke-width="1.5" marker-end="url(#ar)"/> <text x="696" y="243" text-anchor="middle" fill="#A79C8E" font-family="monospace" font-size="9.5">TLS</text> <text x="696" y="152" text-anchor="middle" fill="#A79C8E" font-family="sans-serif" font-size="10.5">no middleware</text> <text x="696" y="166" text-anchor="middle" fill="#A79C8E" font-family="sans-serif" font-size="10.5">in this path</text>

<text x="100" y="330" text-anchor="middle" fill="#A79C8E" font-family="sans-serif" font-size="10.5">never holds a</text> <text x="100" y="344" text-anchor="middle" fill="#A79C8E" font-family="sans-serif" font-size="10.5">provider credential</text> </svg>


2. Every boundary, and what guards it

Boundary What crosses it Control on the crossing
Your people → your browser Whatever your team types or uploads Sign-in required for every non-public route; optional two-factor; roles re-read from the database on every request
Browser → Cloudflare Requests and content, over TLS TLS 1.2 or better; plain HTTP is upgraded; connections below TLS 1.2 are refused
Cloudflare → our application The same traffic, filtered The origin firewall accepts connections only from Cloudflare's published address ranges, so the edge cannot be reached around. There is no alternate public entry point
Application → database Your records TLS enforced to the database; the database is not reachable from the public internet; every read and write carries your organization's identifier
Application → backups A periodic encrypted copy Encrypted; written to storage separate from the database; self-validating on creation; expire automatically at 35 days
Application → model providers The prompt and the context the task needs Server-side only, direct, with no middleware in the path. Each provider is contractually barred from training on it. Your browser never holds a provider credential
Application → your connected accounts Only content you have approved for publishing Publishing is locked until a named person signs off

3. What each hop actually carries

To the model providers. The task's prompt and the context it needs — the relevant part of your Knowledge Base, your brand profile, the brief. Not your member list, not your audit trail, not another client workspace's material. Voice sessions are processed in memory for forwarding and discarded; we keep the transcript, not the audio.

To the database. Your records, scoped to your organization and, within it, to the client workspace they belong to.

To the audit trail. Metadata about what happened — who, what, outcome — written append-only. Never payloads, never passwords, never keys.

To backups. A copy of the database, encrypted, on a fixed schedule.


4. What never crosses a boundary

  • Provider credentials never reach your browser. All AI calls are made server-side.
  • No secrets in the frontend bundle, and none written to logs.
  • No path from one organization's data to another. The organization is a required parameter of the data layer rather than a filter someone remembers to apply.
  • No administrative console, impersonation feature, or internal viewer of customer content — those capabilities do not exist in the product, so there is no boundary for them to cross.
  • No aggregator, orchestration service, analytics vendor, or prompt-logging proxy between us and a model provider. We used an aggregation layer previously and removed it deliberately.

5. Where data comes to rest

Location What is there How long
The database Everything you create in the product As long as your organization is active — we do not auto-expire your content
Encrypted backups A recent copy of the above 35 days, enforced by a storage lifecycle rule rather than by anyone remembering
Model providers Inputs and outputs, transiently Deleted within 30 days under their own terms; never used for training
Your export A complete structured copy Yours, whenever you ask — self-service, no request needed

On deletion, the live copy goes immediately and cascades, recorded in your audit trail before it completes. On termination you have 30 days to export before deletion begins.


Change log

  • v1.0 (21 August 2026) — first issue. Derived by redaction from the Cloud Security Posture and Data Governance documents; boundary table verified against the running system, including the origin's Cloudflare-only restriction.