> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.instabase.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.instabase.com/_mcp/server.

# Network architecture requirements

> For self-managed AI Hub deployments in a VPC environment, AI Hub requires specific outbound network connectivity.

Network requirements for AI Hub enable usage metering, AI model endpoints, and optional integrations.

For SaaS customers, Instabase configures your deployment appropriately. Customers who manage their own deployment in a Virtual Private Cloud (VPC) must configure outbound network connectivity for essential services.

## Required egress connections

Certain connections are required for proper functioning of AI Hub in your environment.

### Metronome usage metering

To enable real-time usage tracking and billing data transmission, your environment must be connected to Instabase Metronome API endpoints.

| Attribute  | Details                                                                     |
| ---------- | --------------------------------------------------------------------------- |
| Protocol   | HTTPS (Port 443)                                                            |
| Endpoints  | `*.metronome.com`                                                           |
| Frequency  | Per request billing calls                                                   |
| Data Type  | Consumption data                                                            |
| SLA Impact | Critical. If this connection is blocked, your AI Hub deployment is blocked. |

#### Network requirements

* Allow outbound HTTPS to Instabase telemetry servers.

* Ensure that firewall rules permit continuous data transmission.

* Configure the NAT gateway for private subnet deployments.

### Azure Cognitive Services billing

To enable Microsoft Azure service billing and authentication, your environment must be connected to Azure Cognitive Services billing endpoints.

| Attribute  | Details                                                               |
| ---------- | --------------------------------------------------------------------- |
| Protocol   | HTTPS (Port 443)                                                      |
| Endpoints  | `*.cognitiveservices.azure.com`, `management.azure.com`               |
| Frequency  | Per-request billing calls                                             |
| Data Type  | Digitization consumption data                                         |
| SLA Impact | Critical - blocking this connection blocks digitization of new files. |

#### Network requirements

* Allow outbound HTTPS to Azure management and cognitive services domains.

### LLM provider access

To enable access to large language model (LLM) services for AI processing capabilities, your environment must be connected to at least one supported LLM provider endpoint.

| Attribute  | Details                                                                   |
| ---------- | ------------------------------------------------------------------------- |
| Protocol   | HTTPS (Port 443)                                                          |
| Frequency  | Per AI request processing                                                 |
| Data Type  | Model prompts, responses, embeddings                                      |
| SLA Impact | Critical - blocking this connection prevents AI processing functionality. |

#### Provider requirements

* You must make all models of your chosen provider available to AI Hub.

* For details about model usage and requirements, see [supported LLM providers](/policies/llm-providers).

| Provider                       | Endpoints                                                    | Authentication                            |
| ------------------------------ | ------------------------------------------------------------ | ----------------------------------------- |
| OpenAI API                     | `api.openai.com`                                             | API key                                   |
| Azure OpenAI API               | `*.openai.azure.com`                                         | API key or user-assigned managed identity |
| AWS Bedrock (Anthropic Claude) | `bedrock-runtime.*.amazonaws.com`, `bedrock.*.amazonaws.com` | AWS IAM roles and policies                |

#### Network requirements

* Configure egress access to at least one of the supported LLM provider endpoints.

* Ensure adequate bandwidth for AI model requests and responses.

* For private deployments, configure NAT Gateway or PrivateLink as appropriate.

* Review [supported LLM providers documentation](https://docs.instabase.com/policies/llm-providers) for current model requirements and compatibility.

## Optional egress connections

### Google Vision API

> **Info**
>
> Enterprise accounts only.

To enable advanced language OCR capabilities for complex document processing, connect your environment to the Google Cloud Vision API endpoints. Advanced OCR capabilities include:

* Processing documents with complex layouts.

* Multi-language document recognition.

* Advanced table extraction requirements.

| Attribute | Details                                     |
| --------- | ------------------------------------------- |
| Protocol  | HTTPS (Port 443)                            |
| Endpoints | `vision.googleapis.com`, `*.googleapis.com` |
| Frequency | On-demand for OCR processing                |
| Data Type | Document images, OCR results                |

### Custom integration endpoints

For custom integrations with your own systems and APIs, use your specified endpoints.

| Attribute | Details                                          |
| --------- | ------------------------------------------------ |
| Protocol  | HTTPS/HTTP (Ports 80, 443, or custom)            |
| Endpoints | Customer-defined                                 |
| Frequency | Based on integration requirements                |
| Data Type | Extracted data, webhook notifications, API calls |

Common integration patterns:

* Webhook notifications to your systems.

* API calls to your databases or customer relationship management (CRM) systems.

* File uploads to your storage systems.

* Authentication with your identity providers.

### Customer storage and connector ecosystem

You can access your data sources and storage systems with AI Hub connectors.

AI Hub supports extensive data connections for input sources, output destinations, and default storage. See the [data connections configuration guides](https://docs.instabase.com/admin/data-connections) for detailed information.

#### Connection scope guidelines

* Configure connections at workspace level for access separation.

* Use organization-level connections only for default storage drives.

* Avoid organization-level connections as shortcuts for cross-workspace access.

#### Authentication requirements

Use Role-Based Access Control (RBAC) with service principals, IAM roles, or managed identities.

Use storage keys and connection strings only when RBAC isn't supported by the target system.

#### Network requirements by storage type

| Cloud Storage Type   | Port/Protocol    | Authentication Recommendation                |
| -------------------- | ---------------- | -------------------------------------------- |
| AWS S3               | Port 443 (HTTPS) | Use IAM roles instead of access keys         |
| Azure Blob Storage   | Port 443 (HTTPS) | Use managed identity or service principal    |
| Google Cloud Storage | Port 443 (HTTPS) | Use service account with minimal permissions |
| SharePoint Online    | Port 443 (HTTPS) | Use Azure AD application registration        |

## Troubleshooting

### Metronome connection failures

* Verify that the security group allows outbound HTTPS.

* Check the NAT gateway configuration for private subnets.

* Confirm that no corporate firewall blocking is active.

### Azure billing failures

* Validate the Azure service principal permissions.

* Check for proxy authentication requirements.

* Verify the DNS resolution for Azure endpoints.

## Compliance and data privacy

Review these data protection measures and regional considerations when configuring your network.

### Data in transit

* All communications use TLS 1.2 or higher.

* Only aggregated metrics are transmitted to Metronome and Azure.

* No document content is transmitted for billing purposes.

### Regional considerations

* Configure endpoints appropriate for your deployment region.

* Consider data residency requirements for optional services.

* Review corporate policies for cross-border data transmission.

## Support and documentation

For additional network configuration assistance:

* Review the [connector documentation](https://docs.instabase.com/admin/data-connections).

* Contact Instabase support for custom integration requirements.

* Validate your network configuration during deployment planning phase.