Skip to content
/docs

DPO FAQ

Common data protection questions for Veto BYOC.

Does Plaw receive policy or decision content?

No for BYOC. Policy bodies, decisions, tool-call args, approval details, Slack content, prompts, env vars, secrets, agent IDs, and end-user IDs stay in the customer plane.

What does the license heartbeat send?

Exactly six fields: instance_uuid, license_id, decision_count_30d, sdk_version, operator_version, and timestamp.

Can we run without egress?

Yes. Air-gapped operation is supported under the enterprise agreement; details and license cadence are scoped per engagement.

Does Plaw need cloud account access?

No. BYOC is outbound HTTPS only. Plaw does not assume roles, use cross-account IAM, or impersonate cloud identities.

Where is customer data stored?

Cloud/SaaS stores data in the Plaw plane. BYOC keeps customer data in a customer-owned storage backend in the customer plane; backend options are scoped per agreement.