TelonicDocs
English

Integrations

AWS

How Telonic runs inside your own AWS account, with every component in your environment and your own encryption keys.

On this page
  1. What running in your own AWS account means
  2. How it connects
  3. Permissions
  4. In practice
  5. What your team controls
  6. Related

If your security policy requires customer data to stay in infrastructure your organisation controls, Telonic can be deployed into your own AWS (Amazon Web Services) account. Every Telonic component runs inside your environment, in the AWS region you choose, and stored data can be encrypted with keys you manage. Only operational health signals, which contain no customer data, are sent to Telonic, and you can switch them off. Your organisation owns the account; Telonic deploys and runs the software in it.

What running in your own AWS account means

AspectHow it works
Where it runsEvery Telonic component runs inside your AWS account, in the AWS region you choose. The region is recorded in your agreement
Where processing happensAll processing for your deployment runs in the region you choose, unless you explicitly choose a language model provider outside it
EncryptionConnections use TLS (Transport Layer Security, the standard encryption for data in transit) version 1.2 or higher. Stored data is encrypted with AES-256 (the Advanced Encryption Standard, using 256-bit keys)
Your keysYou can use customer-managed keys (encryption keys your organisation creates and controls) held in AWS Key Management Service
What reaches TelonicOperational health signals only, containing no customer data. You can switch them off
BackupsBackups and disaster recovery copies are encrypted and stay in the same country as your deployment

How it connects

Your cloud team provides the account, or resources in an account set aside for Telonic, and grants the access described below. Telonic deploys and runs the software there, and the computing capacity your deployment needs is sized with your team during implementation. Your agents connect to your other systems from inside your own environment, over routes your network team controls.

Telonic engineers reach your deployment only when you approve it. Access is limited to named engineers, working from the UAE or your chosen country, and is time-limited and logged. If you later decide to move to another hosting option, the move is carried out as a migration agreed with you in advance: data is moved encrypted and never leaves the countries your agreement permits.

Telonic's own UAE and Saudi Arabian hosting options also use major cloud providers' data centres in those countries. For those options, the provider and region are named in your agreement. See Hosting and data residency.

Permissions

PermissionNeeded forDefault
Deploy and update Telonic components in the resources set aside for themInstalling, updating and supporting your deploymentEach access needs your approval, and is time-limited and logged
Use of your encryption keysEncrypting stored dataOnly if you choose customer-managed keys
Send operational health signals to TelonicMonitoring the health of your deploymentOn. You can switch it off
Access to other resources in your accountNot neededNot requested

Telonic can only reach what you have granted, and only when you approve it.

In practice

Sahel Crest Properties, a Dubai developer, runs its CRM (the system that holds its customer records) and data platform on AWS.

  1. Its cloud team creates a dedicated AWS account for Telonic in the developer's organisation, in its chosen region, and grants deployment access for the installation window.
  2. Telonic deploys the agent, which connects to the developer's CRM and handover calendar from inside the developer's network.
  3. The security team sets customer-managed keys and decides to switch off operational health signals, relying on its own monitoring.
  4. For each later update, the developer approves the access, and every session is logged.

What your team controls

  • The account, region and network routes.
  • The encryption keys, and whether to use them.
  • Whether operational health signals are sent, and each approval of engineer access.

Product names and logos are trademarks of their owners. Their mention shows systems Telonic connects to and does not imply partnership or endorsement.