Skip to main content

Enterprise

Built for the organizations that ask the hardest questions first.

Curated sits next to the data your organization cares most about, under the permissions you already built, on infrastructure you choose. It is engineered to clear a security review, not to talk its way around one.

  • SOC 2 audited controls
  • Your infrastructure, or ours
  • Never used to train a model

01 / Where it runs

Some data does not leave the building. That is fine.

Where Curated runs is a deployment decision. It is not a different product, and the one that runs on your own hardware is not the cut-down one.

Inside your perimeter

When the data cannot leave the building, Curated runs where the data already is. Same product, same features. Where it runs is a deployment decision, not a lesser tier of the software.

On our managed service

Your organization separated from every other one, at the database schema rather than by a filter in a query that somebody could forget to write. Most teams start here, and many stay.

02 / What your security team will ask

Six answers, and none of them are “we take security seriously”.

The questions they will ask are the questions we would ask. Here they are answered before the call, so the call can be about something else.

Isolated per organization

Separation is structural, not a WHERE clause. Your tenant is your tenant.

Never used to train a model

Not to improve the product, not to improve a model, not for anyone else's benefit. There is no version of this where that changes.

Your identity, your permissions

People sign in with the ArcGIS account they already have. Curated reads what they are already allowed to read, and nothing else. It never gets a service account on your portal.

Entitlements you control

Which data sources an organization can reach is set per organization. A source you are not licensed for is not there to be reached, whatever anyone types into the box.

Bring your own model keys

If your organization has already decided which model it trusts, that decision stands. The provider relationship stays yours, and so does the spend.

Nothing written back without you

Curated does not modify your portal items. Whatever it does to a map, it does in the view, in front of the person, and it can undo.

03 / Governing the answer, not just the data

Locking down the data is the easy half.

The harder question is what happens when an AI hands somebody in your organization a number and they act on it. That is a governance problem, and most tools do not have an answer.

The method is inspectable

An answer that cannot be audited is an answer your risk team should not accept. Every playbook names its factors, its weights and its disqualifiers, and Curated says which one it intends to use before it runs it.

Every number keeps its source

The provider, the vintage and the method travel with the figure into the report. When somebody asks where it came from six months later, there is an answer.

Your methodology, encoded

We sit with the analysts who already make the decision well, work out how they actually weigh it, and write it into a playbook the rest of the organization can run. What comes out belongs to you.

04 / How we work with your security team

Engineered under SOC 2 audited controls.

The organization that builds and operates Curated works under an audited control environment: access management, change control, monitoring and incident response, all formally assessed rather than asserted on a marketing page.

Your security team will want the detail, and they should have it. Bring them into the conversation early and we will walk them through the control environment, the deployment model, and the documentation they need to sign this off.

What we bring to the review

  • The control environment behind the engineering, and how it is assessed.

  • The deployment model, whether it runs in your perimeter or ours.

  • Exactly what Curated can reach in your portal, and the permissions that bound it.

  • Where your data lives, who can see it, and the fact that it never trains a model.

Enterprise FAQ

The questions procurement asks, answered before the call.

  • What is your security and compliance posture?

    Curated is built and operated under SOC 2 audited controls, covering access management, change control, monitoring and incident response. Your organization is isolated at the database schema, your data is never used to train a model, and Curated operates under the ArcGIS permissions you already built rather than a service account. Bring your security team in early and we will take them through the control environment and the documentation your process requires.

  • Can we run Curated inside our own environment?

    Yes. When the data cannot leave your perimeter, Curated deploys inside it. Raise it early, because it changes how a rollout is scoped.

  • Do you train models on our data?

    Never. Not to improve the product, not to improve a model, not for anyone else's benefit. Your data answers your questions and does nothing else.

  • What can Curated reach in our ArcGIS portal?

    Exactly what the person using it can already reach. Each user connects their own ArcGIS account, Online or Enterprise, and Curated operates as that user. Your groups and your item permissions apply, unchanged, which means you never hand a vendor a service account.

  • Which model does it use, and where does our data go?

    Curated is model-agnostic. Bring your own keys and the provider relationship is yours, with the spend visible to you. If you have standardised on a particular model or a private deployment, we work with that.

  • Can our security team run their own review?

    Yes, and we would rather they did. Bring them in early and we will answer their questions directly, in detail, with the documentation your process requires.

  • How is Enterprise priced?

    It is scoped to the rollout rather than quoted from a table, because the shape of the deployment changes the shape of the number. Where it runs, how many people touch it, which data sources you license, and whether we build playbooks to your methodology all move it. Talk to us and we will scope it properly.

Bring your security team. Early, not late.

The questions they will ask are the questions we would ask. Answering them in the first meeting is faster for everyone than discovering them in procurement three months later.

We will answer their questions directly, and in detail.