For the organizations Procela is built for, one constraint dominates every architecture decision: the data cannot move. Export-controlled engineering data, CUI, and regulated health and financial records can't be copied to a vendor's cloud for processing. So Procela is designed around a simple principle — governance comes to the data, not the other way around.
The no-egress principle
Procela Edge Agents run inside your environment. They profile and govern data where it lives and send only metadata — classifications, lineage, policy state — back to the platform. Source records never cross your perimeter. This is what makes Procela viable in ITAR, CMMC, CUI, and HIPAA contexts where data residency is non-negotiable.
How Edge Agents work
Agents deploy via Kubernetes or Helm into your infrastructure — a VPC, an on-premise cluster, or a secured enclave. Rather than pulling data out to scan it, they perform push-down profiling: the analysis executes next to the source, and only the resulting metadata is returned.
Identity: mutual TLS
Every agent authenticates to the platform with mutual TLS. Both sides of the connection prove their identity cryptographically, so a rogue agent can't impersonate a real one and the platform can't be spoofed. Agent identity is also the anchor for the audit trail — every action an agent takes is attributable to a verified principal.
Tamper-evident audit logs
Agents maintain append-only, tamper-evident logs of everything they do: what was profiled, what was classified, what policies were evaluated. Because the log is tamper-evident, an auditor can trust that what they're reading is what actually happened.
What actually leaves the perimeter
Only metadata: asset identifiers, classifications, ownership and stewardship assignments, policy decisions, and lineage. No column values, no records, no file contents. If it would be sensitive to move, it doesn't move.
Deployment topologies
- Cloud VPC. An agent in your AWS VPC profiles S3, RDS, Redshift, and other sources in-region.
- On-premise. An agent inside your data center reaches legacy databases that never touch the internet.
- Hybrid. Multiple agents across environments report into one governance program, giving you a single view without consolidating the data.
The result
You get a unified, audit-ready governance program across every source — while your data stays exactly where your security and compliance teams require it to be.