# Enterprise Deployment Figures
Enterprise Operating Model
AppSec, platform, product, data, governance, and engineering teams need explicit ownership across the AI security lifecycle.
Operating model assigning mapping, testing, control, evidence, and decision responsibilities across AppSec, platform, product, data, governance, and engineering teams.
- AppSec and Security
- Own threat and evidence interpretation
- Prioritize qualified risk
- Define security acceptance criteria
- AI and Platform
- Own shared model, retrieval, tool, and identity controls
- Provide shared telemetry and policy hooks
- Product
- Own user and workflow behavior
- Approve product tradeoffs and launch conditions
- Data and Privacy
- Own data, tenant, retention, and provenance boundaries
- Approve sensitive-data use and external sinks
Deployment Control Spectrum
Hosted, local-worker, sidecar, and air-gapped models trade operating simplicity for customer control and isolation.
Four deployment models ordered from hosted service through local worker and embedded sidecar to private or air-gapped deployment.
Enterprise Evidence Package
Enterprise delivery should preserve machine-readable findings, retest records, control evidence, and executive reporting in one traceable stack.
Layered enterprise evidence package from technical evidence through findings, remediation and retest records, governance mapping, and executive reporting.