FDE ACADEMY · MODULE 03 · LESSON 02
Where it runs: the building, your tenancy, or a vendor
Three solution classes and the ladder between them. Custody is not the same as control, and crossing into your own cloud account is still a crossing.
- Effort
- About an hour of reading and comparison, no hardware needed.
- Skills
- aws · azure · compliance-governance
Free and self-paced. No certification is offered.
01Three classes, one question
Self-hosted, private cloud and enterprise SaaS are not points on a quality scale. They are three answers to one question: whose systems hold the data while the work is done. That question is what your constraints record from module 01 answers, and it is why the constraint conversation comes before the tool conversation.
Each class has an honest case. Self-hosted when the data may not leave; private cloud when it may leave the building but not your control; SaaS when the vendor’s written commitments are sufficient and the operational burden is what you are buying your way out of.
02The transfer ladder
This site derives a transfer verdict from the architecture rather than asserting one: none, metadata only, some, or yes. It is computed from the edges of the diagram, so a recipe cannot claim that nothing leaves while drawing an arrow to a vendor.
The rung worth understanding is the one people argue about. Sending documents into your own cloud tenancy is not “none”. You still control the account, but the documents have left the building, and that is exactly the fact a data-processing question turns on. A deployment that answers this wrongly in a security questionnaire loses more time than one that answers it honestly.
- None — no outbound edge carrying company data. Model weights downloaded once do not count and the note says so.
- Metadata only — something crosses, but not the content.
- Some — an outbound edge into a tenancy or system you or a third party operate.
- Yes — the content is processed by a third party as the normal path.
03Reading a diagram like a reviewer
Open a recipe’s architecture and look at the boundary box first, then at every arrow that crosses it. For each crossing ask what is on it, who receives it, and what contract governs the receipt. That is the whole method, and it is the same method a customer’s risk function will apply to your design.
Do it on someone else’s design before you do it on your own. Comparing two recipes that reach different verdicts is the fastest way to see what causes the difference.
04Do this
PRACTICAL TASK
Compare two architectures and explain the different verdicts
Take one self-hosted and one private-cloud recipe, read both architectures, and write the specific reason their external-transfer verdicts differ.
What you need
- No hardware — this is reading and writing
Steps
- 01
Read the flagship self-hosted architecture and note the boundary label and the transfer stamp.
- 02
Read the private-cloud equivalent and note its boundary label and stamp.
- 03
List every edge that crosses a boundary in each diagram, and what travels on it.
- 04
Now read the enterprise SaaS recipe and identify which of your module 01 constraints it would fail for your customer, and which it would satisfy.
- 05
Write one paragraph a non-engineer could read, naming what leaves and what does not for the option you would recommend.
You are done when
- You can state the transfer verdict for all three recipes and the edge that causes each one.
- You can explain why a deployment inside your own cloud account is not “none” without using the word “compliance”.
- Your paragraph names a recipient for every crossing, not just a direction.
05Where these facts live
This lesson does not restate anything that is already recorded with its evidence elsewhere on the site. These are the pages it leans on.
- Private cloud RAG
The same retrieval deployment in a tenancy you control, and the verdict that follows from it.
- Enterprise SaaS assistant
The vendor-hosted option, with the five conditions under which this site says consider it.
- AI-assisted candidate workflow
A single-region private-cloud deployment, and the reasons that tenancy was chosen over the other two.
Ticks are stored in your browser only. They are not sent anywhere, they are not attached to an account, and clearing your browser data removes them.