Integrations
Cloud hosting
How Telonic runs your deployment inside your own cloud account on Microsoft Azure, AWS, Google Cloud or Core42, and how regional hosting works.
On this page
Some organisations need every part of a deployment to run inside infrastructure they already own and have already approved. For them, Telonic deploys and runs the software inside your own cloud account, on Microsoft Azure, AWS, Google Cloud or Core42. Every component runs in your environment, your keys protect your data, and each time a Telonic engineer needs access, your team approves it. If you prefer Telonic to operate the infrastructure, the UAE and Saudi Arabian regional options run on major cloud providers' data centres in those countries.
Where your deployment can run
| Option | Where it runs | Who operates the infrastructure |
|---|---|---|
| UAE region | Major cloud providers' data centres in the UAE | Telonic |
| Saudi Arabian region | Major cloud providers' data centres in Saudi Arabia | Telonic |
| Your own cloud account | Your account on Microsoft Azure, AWS, Google Cloud or Core42, in the region you choose | You own the account; Telonic deploys and runs the software in it |
| Your own premises | Your own data centre | Your organisation, with Telonic, to your requirements |
For the regional options, the cloud provider and region are named in your agreement. This page covers the providers supported for your own cloud account. The full comparison of all four options is on Hosting and data residency.
Cloud providers supported for your own account
| Integration | What the connection covers |
|---|---|
| Microsoft Azure | Running your deployment in your Azure subscription |
| AWS | Running your deployment in your AWS account |
| Google Cloud | Running your deployment in your Google Cloud project |
| Core42 | Running your deployment in your Core42 environment |
How your own cloud account works
Your organisation owns the account. Your cloud team provides the account, or a dedicated area within it, and the permissions for Telonic to deploy into it. Telonic deploys every component there: the agent, the customer record, the speech and language models, and the connections to your systems. Customer data stays in your account, in the region you choose.
Only operational health signals, which contain no customer data, are sent to Telonic, and you can switch these off. Telonic staff access is limited to named engineers, working from the UAE or your chosen country, time-limited and logged, and each access needs your team's approval.
All processing for your deployment runs in the region you choose, unless you explicitly choose a language model provider outside it. Which providers and models are available in your region is confirmed during implementation, and named in your agreement. See Language models.
The technical detail
Stored data is encrypted with AES-256 (the Advanced Encryption Standard, using 256-bit keys), with keys held in your cloud provider's key management service (the cloud service that creates, stores and controls access to encryption keys). Customer-managed keys (keys your organisation creates and controls, and can revoke) are supported. Connections use TLS (Transport Layer Security), version 1.2 or higher. Backups and disaster recovery copies are encrypted and stay in the same country as the deployment.
Your team signs in through your own identity provider (the system that manages your staff's logins), with SAML 2.0 or OpenID Connect (two standards for single sign-on, which lets staff use one work login) and multi-factor authentication (a second check beyond a password). The computing resources the deployment needs are sized with your cloud team during implementation.
Permissions typical for this category
| Permission | Needed for | Default |
|---|---|---|
| Deploy and update the Telonic software in a named account or area | Running and maintaining your deployment | Granted to Telonic's deployment role, scoped to that area |
| Engineer access to the running deployment | Support and incident response | Needs your team's approval each time, time-limited and logged |
| Use of your key management service | Encrypting stored data with your keys | Granted to the deployment only |
| Access to the rest of your cloud estate | Not needed | Not granted |
In practice
A Saudi insurer's security policy requires customer data to stay in infrastructure it controls.
- The insurer chooses its own cloud account, in a region in the Kingdom, and its cloud team creates a dedicated area for the deployment.
- Telonic deploys every component there. The security team configures customer-managed keys and switches off the health signals.
- During implementation, the insurer confirms which language models and speech providers are available in its region. It keeps every provider in-region.
- Months later, a Telonic engineer needs to investigate a slow connection to the claims system. The insurer's operations lead approves a two-hour access window, and the access is logged.
What your team controls
- The account, the region and the resources.
- The encryption keys, including revoking them.
- Whether health signals are sent to Telonic.
- Every instance of Telonic engineer access.
Related
- Hosting and data residencySecurity and data protection
- Deployment separationSecurity and data protection
- EncryptionSecurity and data protection
- Access control and single sign-onSecurity and data protection
- What we need from your IT teamIntegrations
Product names and logos are trademarks of their owners. Their mention shows systems Telonic connects to and does not imply partnership or endorsement.