Architecture // client-contained perimeter

Bank-grade isolation for distributed engineering.

Engineers in Brazil work inside the client’s own virtual environment, with credentials the client issues and can revoke in seconds. Nothing is exported. Nothing is stored locally. The enterprise keeps complete control of its perimeter, and gains a world-class team inside it.

CLIENT ENVIRONMENT · EUVirtual desktopHosted, logged and revoked by the clientSource codeDataSecretsData at rest stays here.Nothing is exported, synced or cached.DISPLAY ONLYEngineer deviceBrazil · holds no dataSESSIONNEVER ON THE PATHLocal diskPersonal emailCloud driveUnapproved AI

Client-contained perimeter

Zero data persistence on Brazilian disks

The simplest way to secure data across borders is to never move it. The engineer’s laptop is a window into the client’s environment, never a copy of it.

Access path // session onlyData at rest: client environment
  1. HOP 01 · BRAZIL

    Engineer device

    Encrypted and locked down. Display and input only. Holds no client data.

  2. HOP 02 · CLIENT

    Identity and MFA

    Client-issued credentials per named engineer. Revocable in seconds.

  3. HOP 03 · CLIENT

    VDI or VPN gateway

    The only route in. Logged and monitored by the client’s own tooling.

  4. HOP 04 · CLIENT

    Client systems

    Code, data and secrets live here and stay here. Nothing is copied out.

Never on the path: SolerWorks systems, partner systems, personal email, messaging apps, cloud drives or unapproved AI tools.

Network data flow topology

Follow the data. Follow the direction.

Two views of one structure. In both, SolerWorks governs the process and holds none of the data.

Data flow

The client’s systems hold the data. Engineers see it through a session the client hosts, with credentials the client controls. SolerWorks is the accountable data processor for that access and never takes custody of a single record.

  • No hosting, storage, backup or transmission by SolerWorks.
  • No copying, downloading, screenshots or forwarding by engineers.
  • Every engineer is onboarded to these rules before access is issued.
Data flowPersonal data stays in client systems. The team uses client-issued credentials. The DPA covers the processing.Enterprise clientController. Pays the partner.PartnerSources, funds and directs the teamSolerWorksContracting entity and processorDelivery teamWorks inside the client environmentDPA covers the processingSolerWorks is processor of recordClient-issued credentialsPersonal data stays in client systems. SolerWorks hosts none of it.

Swipe sideways to see the full diagram.

Data flow. Data stays in client systems. SolerWorks governs the access.

Direction flow

The client sets technical priorities through its own ticketing and access systems. The partner leads the team day to day. SolerWorks stays out of the work entirely, which keeps the chain of command short and clear.

  • Engineers act only on the client’s documented instructions.
  • Delivery leadership stays with the partner.
  • SolerWorks is administrative. It directs no one.
Direction flowThe client directs technical priorities and issues processing instructions. The partner hires and manages the team.Enterprise clientController. Pays the partner.PartnerSources, funds and directs the teamSolerWorksContracting entity and processorDelivery teamWorks inside the client environmentDocumented instructionsController to processorDirects technical prioritiesLeads day to daySolerWorks is administrative only. It does not direct the work.

Swipe sideways to see the full diagram.

Direction flow. The client directs priorities. The partner manages the team.

Control baselines

Isolation, credentials and hardware

Three layers, each with a clear owner. The full split of responsibilities is set out in how it works.

VDI and VPN virtual isolation

All work happens inside the virtual desktop, VPN or managed device the client designates. The environment is the client’s, configured to the client’s own standard.

Operated by

The enterprise client

Credential management

One credential set per named engineer, under the client’s own multi-factor policy. No shared logins, no shared sessions. SolerWorks requests removal the day a role ends.

Operated by

Client issues and revokes. SolerWorks tracks.

Client-provisioned workspace

The client provisions and manages the workspace to its own standard: a corporate device, a virtual desktop or a secure VPN tenancy. Before credentials are issued, each engineer completes security onboarding and attests that the physical endpoint they work from has full-disk encryption, automatic screen lock, a supported and patched operating system, and endpoint protection.

Operated by

Client provisions and manages. Engineers attest, and SolerWorks keeps the record.

Security controls

The control register, at a glance

The same register is tailored to each client account and shared with its security team.

AreaControlOperated byEvidence
PerimeterAccess only through client-issued credentials and the designated VDI or VPN.ClientData processing agreement
PerimeterNo client data stored outside the client environment.SolerWorksEngineer onboarding records
IdentityMulti-factor authentication on every client-issued account.ClientClient identity provider
PersonnelSecurity onboarding before access. Live register of name, role, systems and access dates.SolerWorksPersonnel register
PersonnelSecurity and privacy training, completed before access.SolerWorksEngineer onboarding records
WorkspaceCorporate device, virtual desktop or VPN tenancy, provisioned and managed by the client.ClientClient asset and access records
EndpointFull-disk encryption, screen lock, supported operating system and endpoint protection on the physical device, attested before credentials are issued.Engineer and SolerWorksSigned endpoint attestation
IncidentsEngineers report any suspected event to SolerWorks at once. SolerWorks notifies the client without delay, which protects the client’s 72-hour regulatory window.SolerWorksIncident notification form
OffboardingRevocation requested the day a role ends. Signed deletion certificate.SolerWorks and clientDeletion certificate

Cleared for EU–Brazil data flows

Since January 2026 the European Union and Brazil recognize each other’s data protection as adequate, so remote access from Brazil needs no extra transfer paperwork. Standard contractual clauses are built into every agreement as an automatic fallback.

Offboarding and deprovisioning protocol

Clean exits, certified

When an engineer rolls off, or an engagement ends, SolerWorks runs a seven-step checklist. Every step has an owner, a completion date and an evidence reference.

The protocol closes with a signed deletion certificate, delivered to the client’s security team. Because no data ever left the client environment, the certificate is simple: nothing was retained, by anyone.

  1. Access revoked

    SolerWorks requests revocation the day the role ends. The client switches it off.

    Client
  2. Devices and tokens returned

    Any client hardware, security key or token goes back.

    SolerWorks
  3. Register updated

    The personnel register records the exact revocation date.

    SolerWorks
  4. Zero retention confirmed

    Each engineer confirms in writing that they hold no client data.

    SolerWorks
  5. Open requests handed over

    Any pending privacy request passes to the client.

    SolerWorks
  6. Accounts settled

    Final statement between the partner and SolerWorks. Nothing is billed to the client.

    Partner · SolerWorks
  7. Records archived

    Audit records are archived and the deletion certificate is issued.

    SolerWorks