Your data. Your cloud. Your rules.
DEHA Lab is built around data sovereignty. The data side runs on your own infrastructure and we keep only the operational layer. The intelligence you build is a portable whole too, so nothing here locks you in.
Bring Your Own Cloud
Your data stays on your own infrastructure and never leaves it. We only run the operational layer on top.
Personal data protected
Sensitive details and personal data (PII) are detected and masked automatically, so they stay private.
Roles and access control
Fine-grained roles, single sign-on, and API keys put you in control of who can do what.
Isolation and audit
Every workspace is fully isolated, with usage limits and a complete, auditable activity trail.
Eight controls, all on by default
Not a policy document. Each of these is a control the platform applies on every run.
Installed on your side
The platform runs on your own infrastructure. Your business data is read where it already lives and is never copied out to us.
Secrets stay encrypted
Connection details and keys are stored encrypted and decrypted only at the moment they are used. A resolved secret never reaches a log line.
Who can do what is explicit
Roles, single sign-on and API keys. Which agents, flows, screens and tables a person can reach are four separate limits, not one blanket permission.
Every workspace is separate
Workspaces are isolated from one another all the way down: data, configuration and usage counters never share a shelf.
A sensitive step asks first
Before an agent takes an action that matters, the flow stops and waits for your decision. Approve it and the run continues exactly where it paused.
Everything leaves a trail
Who changed what and when, and which run produced which result. All of it recorded, and all of it followable along a single thread.
Outbound calls are fenced
The platform only calls out to addresses you have allowed. Your internal network is off limits by default, and outgoing notifications are signed so the receiver can prove they came from you.
Limits are real limits
Usage caps per workspace and a ceiling on how much can run at once, so one heavy job cannot starve everything else on the system.
An agent runs inside your rules
An agent is the part of the platform that acts on its own, which makes it the part with the most limits drawn around it. These six apply to every run, and none of them is something the agent can turn off.
It only holds the tools you gave it
You pick which tools and which flows an agent may use. Everything outside that list is taken away before the model is even asked, so the agent never learns those tools exist.
It sees no more than you
An agent working on your behalf carries your access, and cannot widen it at any step. Which tables, which flows, which screens: your limit is its limit, and an agent it hands the work to stays inside the same one.
Only known addresses can trigger it
An endpoint that opens an agent to the outside world can be locked to the IP addresses and ranges you name. A call from anywhere else is refused, and an unsigned one is refused too.
Code runs in a sealed box
When an agent writes code to solve something, that code runs in a single-use container with no route to anything else. The container is destroyed when the job ends.
Personal data is masked on the way out
Whatever an agent sends out is checked for personal data and masked first. If that check cannot run, the answer does not leave. It is on by default and cannot be switched off.
Every run has a ceiling
How long it may run, how many times it may hand work on, how many jobs may run at once and how much it may spend. All four are capped, so an agent cannot loop forever or run up a bill on its own.
Want to set it up? Come build with us.
We deploy DEHA Lab locally for you and walk you through the whole platform, end to end. Pick a time that works and we'll meet on Google Meet.