All posts
Product

Where does the data go when an AI agent asks questions about your product?

A question to a product-knowledge server travels through four places: the Git provider, the vendor's infrastructure, a language-model provider, and the platform that asked. Self-hosting your portal settles the first two at most. Here is what DeployIt's public DPA says about each, and what it leaves open.

The DeployIt Team

We build DeployIt, the product intelligence layer for SaaS companies.

A question put to a product-knowledge server travels through four places: your Git provider, the vendor's infrastructure, a language-model provider, and the platform that asked. The answer comes back along the same road. Self-hosting your developer portal can settle the first two stops at most, and it says nothing about the third.

That is why "where is it hosted?" is the wrong first question for an EU team. The useful one is: at each stop, what moves, and who is named as processing it? This article walks the four stops with what DeployIt's public pages state, and flags what they do not. It is a reading aid for a DPO, not legal advice.

Where this comes from

We read three of our own public pages today: the DPA, the security page and the FAQ that answers "do you store our code content?". Everything we attribute to DeployIt below comes from them. Nothing comes from the server itself, which is in early access and offered through a design partner program.

A DPO's reading of the four stops

Illustrative scenario: a software agency in Lyon connects a support agent to one client's product. Its DPO reads the stops in order, with the DPA open.

Stop 1: the Git provider

The product is connected through a read-only connection to GitHub, GitLab or Bitbucket. The security page says only read scopes are requested: no push, no branch, no write.

  • Settled: DeployIt cannot modify the repository.
  • Open: nothing for this stop. The data starts here and stays under your provider's own terms.

Stop 2: the vendor's infrastructure

The DPA lists "DigitalOcean (EU)" for hosting and infrastructure, and the FAQ says DeployIt does not store file contents: it indexes metadata (commits, authors, files touched, summarised diffs).

  • Settled: the hosting sub-processor and its stated region. Data in transit uses TLS; databases are encrypted at rest.
  • Open: the MCP server is described elsewhere as reading the code to verify an answer. How that reading squares with "does not store file contents" is not spelled out for the MCP server. Two public statements, one gap. Ask which of them governs.

Stop 3: the language-model provider

The DPA names "LLM providers (Claude / OpenAI models)" among the sub-processors. It gives no region for them. The security page adds that a customer can bring their own keys or point to their own model endpoint.

  • Settled: a model provider is a named sub-processor, and the DPA states that customer data is never used to train or fine-tune a model.
  • Open: whether a given MCP answer sends repository content to a provider, and which one. And whether the bring-your-own-endpoint option applies to the MCP server. Neither is stated.

This is the stop that self-hosting cannot move. A portal on your own server, read by an agent that calls a hosted model, sends the page content to that model. The location of the portal stopped being the issue at that moment.

Stop 4: the platform that asked

The answer reaches the agent's platform: a support tool, an assistant, an editor. DeployIt's model is that this platform receives answers, not credentials to the repository. The safe access model and the authentication mechanism explain why.

  • Settled: the platform never holds a repository credential.
  • Open: what that platform then does with the answer. It has its own DPA, and it is a different contract.

What the DPA also gives you, in a few lines

The same page states a 72-hour breach notification, assistance with data subject rights within seven business days, deletion or return of processed data within 30 days of the end of the contract, and one third-party audit per year on request. Those are contract terms. They are not evidence that the controls work, and nobody should read them as one.

We make no compliance claim in this article, and none should be drawn from it.

Are your AI agents answering from today's code?

Does self-hosting still matter?

Yes, for what it actually covers. If your constraint is "no repository content on a vendor's servers", a self-hosted deployment is the only answer that does not depend on a contract. The security page lists a self-hosted option for Enterprise customers. We do not detail it here, and the public pages do not say whether it extends to the early-access MCP server: ask us what applies to your case.

If your constraint is "no data outside the EU", the open point is stop 3, not stop 2.

Six questions to send before the call

  1. Does an MCP answer send repository content to a language-model provider? Which one, in which region?
  2. Is the MCP server covered by the DPA as written, or by an annex?
  3. Can the model provider be replaced by an endpoint we control, for this server?
  4. What does the server keep after answering: the question, the answer, a log?
  5. Who can read those logs on your side, and how long do they stay?
  6. What does a deletion request remove at each of the four stops?

A vendor that answers in writing within the week has told you something. One that answers "we're GDPR-compliant" to all six has told you something else.

Where this sits

This article is about where data moves. The access model is about what an agent may do, the NDA article about client contracts that forbid AI on their code, and calling the server as an API shows what the caller actually receives.

If you want to put these six questions to us on a real project, the design partner program for our MCP server is the place. DeployIt is free during early access; paid plans arrive in January 2027.

Are your AI agents answering from today's code?

Frequently asked questions

Does self-hosting a developer portal keep an AI agent's questions inside the EU?

Only up to the portal. As soon as an agent reads the portal through a hosted language model, the content travels to that provider. The question to settle moves from where the portal runs to where the inference runs.

Where does DeployIt process data?

Its public DPA lists DigitalOcean (EU) for hosting and infrastructure, and names language-model providers as sub-processors without stating their region. Whether a given MCP answer involves a model provider is not described publicly: ask before you rely on it.

Is the DeployIt MCP server covered by the DPA?

The DPA describes the DeployIt service. The MCP server is in early access, as part of a design partner program, and the public pages do not say whether it is covered line by line. Put that question in writing.

Does DeployIt train models on customer code?

Its DPA states that customer data, including source code and repository content, is never used to train or fine-tune AI models, on every plan.

Continue reading