← The Record
For CISOs, CTOs & Operating Executives

Bring Your Own Everything

The vendor you cannot be breached through is the one that never held anything of yours. Why the governance layer should own the structure and none of the substance.

Every CISO reading this has sent the questionnaire. Two hundred questions in a spreadsheet, shipped to a vendor, demanding to know their encryption at rest, their sub-processors, their incident response window, their SOC 2 scope, their data residency, their key rotation schedule. And every vendor reading this has answered one, gaming the soft questions and lawyering the hard ones. An entire industry of assessment exists on both sides of that spreadsheet, and it employs a lot of people, and it reduces, when you boil off the two hundred questions, to a single real one.

What of mine do you hold, and what happens to it when someone breaks into you?

That is the question. Everything else on the spreadsheet is a proxy for it. And the reason the whole ritual is so exhausting, so adversarial, so permanently unsatisfying, is that the usual honest answer to the real question is "a great deal of your data" and "you will read about it in the press before you hear it from us."

There is a way to make the questionnaire boring. Not answered well. Boring. You make most of it not apply.

Agents make the custody problem worse than SaaS ever did

Software-as-a-service taught a generation of security teams to worry about a vendor holding their data. Agents take that worry and pour gasoline on it, because an agent that does real work needs reach that ordinary SaaS never asked for.

A SaaS tool holds the slice of data you put into it. An agent that actually does the job has to touch the repository, read and write the storage, send from the email, query the database, move through the systems where the work lives. So the hosted-agent-platform model does not concentrate one slice of your data behind one vendor's login. It concentrates a working key to all of it behind that login. The blast radius of a breach at a hosted agent platform is not one customer's uploaded documents. It is the union of every system every customer's agents were given reach into. You are not handing a vendor a filing cabinet. You are handing them a master key ring and asking them to keep it somewhere safe, forever, across every customer they will ever sign.

The blast radius of a hosted agent platform is every system every customer's agents can touch, gathered behind one front door for the convenience of whoever kicks it in.

The way out is not a better lock on that front door. It is not building the vendor a stronger vault. It is refusing to move your things into their building at all.

Structure without substance

Picture the alternative concretely, because it is simpler than the questionnaire makes anything sound.

The org deploys into your environment. Your version control stays where it already is; the architecture speaks to your own repository rather than replacing it with a copy on someone else's servers. Your storage stays yours. Your email, your database, all of it stays exactly where it lives today, and the org reaches into your systems the way an employee with the right access would, from inside your walls, not from a tenant across town. The model is your own provider relationship under your own keys, swappable without re-platforming, because governance was never supposed to be married to a particular vendor's model in the first place (Govern the Org, Not the Model is the paper on why the structure has to outlive whichever model is winning this quarter).

So what does the governance layer actually hold? The structure. The org definition, the roles, the gates, the spend caps, the audit lifecycle. The rules of the org and the record of what it did. That is the whole of it. It holds the shape of your company and none of the contents. Structure without substance.

This is the move, and it is worth being precise about why it is a security architecture and not a deployment preference. A vendor that holds your structure and none of your substance is not a smaller target. It is a different kind of target, one whose compromise does not hand the attacker your code, your data, or your keys, because the vendor never had them to lose.

What this dissolves, in the categories you already use

Walk the questionnaire again, but through this architecture, and watch the hard questions stop applying.

Data residency stops being a negotiation, because the data never moved. It is sitting where it has always sat, in your region, under your control; there is no cross-border transfer to document because there is no transfer. Vendor breach exposure stops being a probability you price, because there is no honeypot to breach. The vendor holds no customer code, no customer data, no model keys, so a total compromise of the vendor is a bad day for the vendor and a headline you read with your coffee rather than a call you make to your customers. Model-provider lock-in and the risk-review churn that rides along with every model change stop being the vendor's decision and become yours, made and unmade under your own keys. The sub-processor chain in the data-processing agreement gets short, because the list of parties touching your data does not include the party selling you the governance. And exit risk, the quiet fear under every platform decision, mostly evaporates: your systems were always the system of record, so leaving means switching off the governance layer, not repatriating your life's work from a vendor who has learned to make export slow.

None of that is a feature you switched on. It is the shape of the thing. A questionnaire aimed at custody keeps hitting a wall of "not applicable," not because anyone got clever with the answers, but because there is nothing there to ask about.

The honest trade

I will state the cost plainly, because you would find it yourself the moment the sales gloss wore off, and I would rather you hear it from me.

Self-hosting means you operate the deployment. The vendor cannot magically observe what it does not host, and it cannot reach into your perimeter to hotfix something at 2 a.m., because the entire point is that it has no such reach. Custody reduction and remote convenience are really traded against each other, and this architecture spends the convenience to buy the custody.

The answer to that trade is structural, not apologetic. The same audit lifecycle the org runs for itself is the one your own team operates from, so the visibility you are giving up from the vendor's side is visibility you are gaining on your own (The Wall Is Not a Sign is the paper on why an architecture built for someone else's perimeter is an architecture built to be inspected). A system designed from the first day to run inside a customer's walls is a system designed to be run by someone other than its author. That is a harder thing to build. It is also the only thing that makes the questionnaire boring, and boring is what you actually want from a vendor holding a key to your company.

"Hosted platforms are adding private endpoints and bring-your-own-key"

The strongest counter is that the hosted platforms are converging on this anyway. Private endpoints, customer-managed keys, in-region processing, dedicated tenancy. Give it a year, the argument goes, and the hosted model offers the same custody story without the operational burden.

Be careful, because bring-your-own-key on a platform that still transits and stores your data is a narrower key ring hanging on the same front door. The data still goes there. It is still processed there, still sits there, still concentrated behind the vendor's perimeter; you have simply changed who nominally holds the key to the room your things are stored in. Custody reduction bolted onto a platform inherits that platform's original architecture, the same way any control bolted on after the fact inherits the shape of the thing it was added to (Governance Can't Be Bolted On is the paper on why foundation properties cannot be retrofitted). The question to ask is not who holds the key. It is where the data is. If the answer is still "in the vendor's building," the key ring is a detail and the building is the risk.

The promise you make unnecessary

The series has argued from the start that governance belongs in structure rather than in promises, that a wall you can inspect beats a policy you have to trust. Custody is that same argument turned around to face the vendor.

The strongest data-protection promise a vendor can make is not a well-written one. It is the architecture that makes the promise unnecessary, because there is nothing in the vendor's hands to protect. Bring your own version control. Bring your own storage, your own database, your own email, your own model and your own keys. Let the vendor bring the structure, and only the structure. The safest thing a vendor can hold of yours is nothing at all, and the questionnaire that goes looking for what they hold should come back, at last, boring.

References

  1. SpeyAI, Rise of the Agent Org library. Companion papers: Govern the Org, Not the Model (why structure outlives any one model, and model keys stay the customer's); The Wall Is Not a Sign (architecture built for someone else's perimeter is built for inspection); Governance Can't Be Bolted On (why custody is a foundation property, not a retrofit); Identity for Non-Human Actors (per-agent identity operating inside the customer's own systems).

This paper is part of Rise of the Agent Org, a series by Ed Hoehn, SpeyAI. The full library is at speyai.com/record.

The missing layer

Architecture as governance. See how it runs.