TelonicDocs
English

Integrations

Cloud hosting

How Telonic runs your deployment inside your own cloud account on Microsoft Azure, AWS, Google Cloud or Core42, and how regional hosting works.

On this page
  1. Where your deployment can run
  2. Cloud providers supported for your own account
  3. How your own cloud account works
  4. The technical detail
  5. Permissions typical for this category
  6. In practice
  7. What your team controls
  8. Related

Some organisations need every part of a deployment to run inside infrastructure they already own and have already approved. For them, Telonic deploys and runs the software inside your own cloud account, on Microsoft Azure, AWS, Google Cloud or Core42. Every component runs in your environment, your keys protect your data, and each time a Telonic engineer needs access, your team approves it. If you prefer Telonic to operate the infrastructure, the UAE and Saudi Arabian regional options run on major cloud providers' data centres in those countries.

Where your deployment can run

OptionWhere it runsWho operates the infrastructure
UAE regionMajor cloud providers' data centres in the UAETelonic
Saudi Arabian regionMajor cloud providers' data centres in Saudi ArabiaTelonic
Your own cloud accountYour account on Microsoft Azure, AWS, Google Cloud or Core42, in the region you chooseYou own the account; Telonic deploys and runs the software in it
Your own premisesYour own data centreYour organisation, with Telonic, to your requirements

For the regional options, the cloud provider and region are named in your agreement. This page covers the providers supported for your own cloud account. The full comparison of all four options is on Hosting and data residency.

Cloud providers supported for your own account

IntegrationWhat the connection covers
Microsoft AzureRunning your deployment in your Azure subscription
AWSRunning your deployment in your AWS account
Google CloudRunning your deployment in your Google Cloud project
Core42Running your deployment in your Core42 environment

How your own cloud account works

Your organisation owns the account. Your cloud team provides the account, or a dedicated area within it, and the permissions for Telonic to deploy into it. Telonic deploys every component there: the agent, the customer record, the speech and language models, and the connections to your systems. Customer data stays in your account, in the region you choose.

Only operational health signals, which contain no customer data, are sent to Telonic, and you can switch these off. Telonic staff access is limited to named engineers, working from the UAE or your chosen country, time-limited and logged, and each access needs your team's approval.

All processing for your deployment runs in the region you choose, unless you explicitly choose a language model provider outside it. Which providers and models are available in your region is confirmed during implementation, and named in your agreement. See Language models.

The technical detail

Stored data is encrypted with AES-256 (the Advanced Encryption Standard, using 256-bit keys), with keys held in your cloud provider's key management service (the cloud service that creates, stores and controls access to encryption keys). Customer-managed keys (keys your organisation creates and controls, and can revoke) are supported. Connections use TLS (Transport Layer Security), version 1.2 or higher. Backups and disaster recovery copies are encrypted and stay in the same country as the deployment.

Your team signs in through your own identity provider (the system that manages your staff's logins), with SAML 2.0 or OpenID Connect (two standards for single sign-on, which lets staff use one work login) and multi-factor authentication (a second check beyond a password). The computing resources the deployment needs are sized with your cloud team during implementation.

Permissions typical for this category

PermissionNeeded forDefault
Deploy and update the Telonic software in a named account or areaRunning and maintaining your deploymentGranted to Telonic's deployment role, scoped to that area
Engineer access to the running deploymentSupport and incident responseNeeds your team's approval each time, time-limited and logged
Use of your key management serviceEncrypting stored data with your keysGranted to the deployment only
Access to the rest of your cloud estateNot neededNot granted

In practice

A Saudi insurer's security policy requires customer data to stay in infrastructure it controls.

  1. The insurer chooses its own cloud account, in a region in the Kingdom, and its cloud team creates a dedicated area for the deployment.
  2. Telonic deploys every component there. The security team configures customer-managed keys and switches off the health signals.
  3. During implementation, the insurer confirms which language models and speech providers are available in its region. It keeps every provider in-region.
  4. Months later, a Telonic engineer needs to investigate a slow connection to the claims system. The insurer's operations lead approves a two-hour access window, and the access is logged.

What your team controls

  • The account, the region and the resources.
  • The encryption keys, including revoking them.
  • Whether health signals are sent to Telonic.
  • Every instance of Telonic engineer access.

Product names and logos are trademarks of their owners. Their mention shows systems Telonic connects to and does not imply partnership or endorsement.