Security & deployment

Deploy Definite where your finance data needs to stay.

Definite can run as a hosted service, in your cloud or VPC, on premises, or in an air-gapped environment. We select the deployment model with your security and technical teams.

Deployment

Choose the boundary that fits the workflow.

These five deployment options provide the starting boundary. The exact architecture and controls are scoped with the customer’s security and technical teams.

Definite-hosted
Use Definite as a hosted service while keeping the scope of connected systems and data explicit.
Customer cloud
Run Definite inside your cloud environment alongside the systems and data it needs to connect.
Customer VPC
Place Definite inside a customer-controlled virtual private cloud and network boundary.
On premises
Deploy Definite inside infrastructure operated by your organization.
Air-gapped
Run Definite in an isolated environment when the workflow cannot depend on external network access.
Data boundary

Source systems stay authoritative.

Conceptual architecture view

  1. Source systems

    Existing records stay authoritative

    Definite collects approved data from ledgers, operational systems, warehouses, documents, and spreadsheets without changing the records stored there.

  2. Definite

    Context and decisions stay connected

    The ontology, configured rules, lineage, provenance, and historical snapshots remain attached to the work they produce.

  3. Interfaces

    One context supports each surface

    Dashboards, chat, APIs, BI tools, agents, and workflows use the same mapped financial context.

Definite does not post journal entries, amend source records, or initiate payments in connected systems.

Control lifecycle

Inspect the result from connection through review.

  1. Connect

    Verify the source access boundary.

    Connection setup tests whether source credentials can write and rejects credentials that are over-scoped.

  2. Decide

    Keep financial decisions deterministic.

    Stored rules and parameters calculate figures, evaluate matches, apply thresholds, and produce workflow states. Language models can propose mappings and explanations, but do not calculate or approve financial results.

  3. Retain

    Preserve what is needed to reproduce the result.

    Each run retains its inputs, mappings, rules, parameters, results, source-to-cell lineage, and provenance. Historical snapshots allow a prior period to be rebuilt as it appeared at the time.

  4. Review

    Keep authority and uncertainty explicit.

    Preparer and approver roles remain separate in the data layer. Unreadable fields, non-zero residuals, missing evidence, and cases with more than one valid answer remain visible instead of being forced through.

Architecture review

Confirm the details for the selected environment.

Networking, data residency, retention, encryption, identity, and certification requirements depend on the applicable architecture and agreement. We scope those details with the customer’s security and technical teams during evaluation.