| Customer data | - Design the system so that sensitive data does not transit LangChain infrastructure for normal operation
- Avoid access to customer data in normal operation
| - Own the data in the data plane, including classification, retention, and access controls
- Own the legal and compliance obligations for that data
- Approve any data export or sharing internally
|
| Data residency | - Provision all data plane components and storage only within the AWS region you designate
- Keep customer data out of LangChain-managed infrastructure during normal operation
| - Specify the required AWS region at onboarding
- Communicate any change to your data residency requirements in advance
|
| Secrets management | - Use secret stores in the customer account for runtime secrets
- Reference secrets without persisting sensitive values in the control plane
| - Apply any organization-specific key management requirements
|
| Break-glass access | - Use break-glass access only for incident mitigation, with customer approval and a defined process
- Minimize the duration and scope of that access
- Give advance notice where possible
- Deliver a post-access summary covering timestamps, actions taken, and any data accessed
| - Approve break-glass access when it is required
- Define the internal approval workflow
- Review post-incident access logs and notes
|
| Access audit logs | - Provision the logging infrastructure in your account so LangChain access is recorded, including EKS audit logs
- Do not view, analyze, or alert on those logs on your behalf
| - Retain AWS CloudTrail and account-level logs for all LangChain-assumed roles
- View and analyze those logs, and set up your own alerting on them
- Escalate anomalies to LangChain through the shared support channel
|
| Security incident notification | - Notify you of a confirmed security incident in LangChain-owned infrastructure that affects your deployment, covering the control plane, corporate systems, and the BYOC build and release pipeline
- Share the incident scope, impact assessment, and remediation steps
- Cooperate on joint forensics
- Do not run security monitoring inside your cloud account
| - Deploy and operate security monitoring for the BYOC components in your account, such as EDR, IDS, container security, cloud security posture management, and log aggregation
- Keep that monitoring from affecting the operation of BYOC-managed resources
- Designate a security contact and define internal incident response procedures
- Notify LangChain promptly of any suspected compromise of customer-side credentials or access
|
| Compliance and audits | - Provide documentation on the BYOC architecture and operational model
- Supply audit evidence for LangChain-operated controls, including access logs, change history, security policies, and penetration test summaries
- Support SOC 2, ISO 27001, and equivalent audit programs
| - Own the compliance posture of your AWS environment and all customer-managed controls
- Run or coordinate audits and evidence collection for that environment
|