Run AI Workflows (incl SOC) in Your Own Cloud

by | Sep 23, 2026

Data residency is treated like a compliance checkbox on many AI security evaluations, and that’s backwards. It shouldn’t be a question asked during an evaluation.  Data residency is foundational design decision that underpins whether every other platform feature is trustworthy in the first place.

For many AI security tools, the honest answer is that your logs, alerts, and identity data leave your environment.  They get processed on the vendor’s infrastructure and return an answer back to you. This is the same old trust model that has not worked for years.

 

The question nobody asks until the contract’s already signed

Vague is the tell. If a vendor can’t give you a straight answer about data residency, the honest answer is probably “wherever is cheapest and easiest for us,” not wherever is safest for you. Every hop your data takes outside your custody is a place it can leak, a new party who can be breached on your behalf, and a new item on your risk register. Supplier risk doesn’t go away because the supplier is an AI company instead of a traditional SaaS company.

 

Running AI inside your own tenant is the best kept secret

The alternative is straightforward: run the AI workflow inside your own Azure tenant, so the data never leaves your custody in the first place. Private tenant AI is not a scaled down version of SaaS AI.  It’s the same class of capability, deployed where your data already lives instead of a destination it has to travel to.  As soon as you start running your workflows in a provider’s cloud, you are losing visibility, increasing security risks, and locking yourself into an ecosystem.

Security teams have spent years building governance around who can access their data and where it can go. A SaaS AI tool that pulls data out to a third party for processing sits outside those controls, no matter how good the vendor’s own security is. An AI workload that runs inside your tenant inherits your identity controls and logging.

I’ve seen this play out firsthand with a security team whose data handling rules require that anyone accessing citizen data hold citizenship in that same country. SRA’s analyst team didn’t meet that bar, which would normally have ruled us out entirely, but because the AI agent ran inside the client’s own tenant, the citizenship requirement was satisfied by the environment the work happened in. That’s the practical version of “runs in your environment”: it’s not just a data-residency preference, it can be the difference between a deployment being permissible.

 

Process, not just infrastructure

Keeping data in your own tenant solves the custody problem, but it doesn’t automatically solve the competence problem. A tenant full of AI infrastructure with nobody who knows how to build, tune, and govern workflows on it can turn out to be expensive. The infrastructure decision and the process decision are related but separate, and a lot of the value SRA makes in Digital Workers vs. Personal Assistants applies here: where the data lives is the foundation, but what gets built on top of it is the part that actually does the work.  Many of the AI-for-security platforms say “your data, your cloud” on a slide, but few can actually stand up an AI capability inside that environment that an analyst would trust at 2 a.m.

 

In Conclusion

This delivery model is fundamental to how SRA wants to see the future of SaaS; innovative software solutions that can be securely run and maintained in your private cloud. SCALR AI was built to solve this problem. It runs entirely inside your own Azure tenant, so your data never leaves your custody to begin with, and it’s now available free on the Azure Marketplace, deployed directly into the environment your data already lives in. SRA brings the process and engineering expertise to build real workflows on top of it, not just the infrastructure. If you want to see what that looks like, download SCALR AI and schedule a workshop to start building the workflows that actually help your team.

SCALR AI is now available for free download and deployment into your organization's Azure environment

Your AI security data stays in your cloud. Don’t take that to mean that SCALR AI only works in a Microsoft environment; it can adapt to work with any of your security tools.  Schedule a demo with us to start identifying other opportunities for SCALR AI to enhance your AI security processes.

Mike Pinch
Chief Technology Officer |  Archive

Mike is Security Risk Advisors’ Chief Technology Officer, heading innovation, software development, AI research & development and architecture for SRA’s platforms.  Mike is a thought leader in security data lake-centric capabilities design.  He develops in Azure and AWS, and in emerging use cases and tools surrounding LLMs. Mike is certified across cloud platforms and is a Microsoft MVP in AI Security.

Prior to joining Security Risk Advisors in 2018, Mike served as the CISO at the University of Rochester Medical Center. Mike is nationally recognized as a leader in the field of cybersecurity, has spoken at conferences including HITRUST, H-ISAC, RSS, and has contributed to national standards for health care cybersecurity frameworks.