Resource · Deployment

On-premise and in-region transaction monitoring: what “data never leaves” has to mean

Most vendors now say the data stays with the client. For a licensed firm that claim has to survive four questions: where the database runs, where the model runs, what the vendor’s support staff can see, and what leaves in logs. Below is how Marqib answers them, and what to ask anyone else.

Where the platform runs

Marqib is deployed as a single-tenant installation in the firm’s own cloud account (AWS, Azure or Google Cloud in the firm’s region) or on the firm’s servers. The database, the rules engine, the case files and the audit log live there. The vendor operates no shared environment and holds no client records. The public demo at app.marqib.com is the one exception: it runs on synthetic data in a vendor-hosted environment so that prospects can see the product, and no pilot is ever run there.

Where the model runs, if one is used

Detection never uses a language model. Drafting may, at the firm’s option, and the endpoint is the firm’s choice: Azure OpenAI in the UAE, AWS Bedrock in Bahrain, an open-weights model on the firm’s own servers, or no model at all, in which case the rule-generated draft is the narrative. Before any call, client identifiers, names, account numbers, card and wallet references are replaced by tokens and restored only after the response is received; the record of what was sent is auditable.

Logs, telemetry and support access

Application logs stay in the firm’s account. The platform sends no telemetry to the vendor. Support is provided under a written data processing agreement, through access the firm grants and can revoke, with every session logged. A vendor who will not put this in the contract is selling a hosted product with a residency sticker on it.

Questions to ask any vendor

Which account does the database run in, and who holds the root credentials? Which model endpoint is used for AI features, in which region, and what is sent to it? What leaves the environment in logs, crash reports or usage metrics? Can your support staff see client records, and is that access logged? Can the firm run the platform with the AI features switched off? If it is not in the contract, it is not an answer.

Regulatory context

Saudi Arabia’s PDPL and SAMA’s outsourcing rules, the UAE PDPL alongside DIFC and ADGM data-protection regimes, and Türkiye’s KVKK all permit processing with appropriate safeguards; none of them require a vendor to hold the data. In-region single-tenant deployment is the simplest way to make the firm’s data-protection and outsourcing assessments short.

Questions

Can Marqib run fully offline?

Yes. With the model provider set to none, the platform has no outbound dependency; the rule-generated draft serves as the narrative.

Who owns the audit log?

The firm. It is a hash-chained table in the firm’s own database; the vendor cannot alter it.

What does the vendor receive during a pilot?

Nothing from the firm’s data. Support works through access the firm grants, under a data processing agreement, with sessions logged.

Read the deployment section for the architecture, or request a pilot in your own cloud account.