| Capability | Standard Service | Enterprise Subscription |
| Security baseline | Encryption, access control, monitoring, vulnerability management and backups | Same baseline plus client-specific control configuration |
| Hosting | Standard service architecture and service region | Dedicated client tenancy or environment in an approved AWS Region |
| Identity | Standard authentication and supported MFA | Client SSO through SAML or OIDC, policy-aligned MFA and enterprise role mapping |
| Encryption | Provider-managed encryption | Optional customer-specific or customer-managed KMS keys |
| Data retention | Standard retention policy | Contracted Client retention, deletion workflow and evidence |
| AI governance | Standard approved-model controls | Client model allowlist, no-training commitment, residency boundary and zero-retention configuration |
| Auditability | Standard operational logging | Client audit exports, reports, API access and agreed retention |
| Compliance evidence | Published security materials | SOC 2, ISO or equivalent evidence under NDA, plus Client control mapping |
| Networking | Secured internet-accessible SaaS | Optional private connectivity, IP restrictions and customer-specific WAF controls |
| Service management | Standard support | Named enterprise support, SLA, incident notification and escalation process |