# SaaS

This page covers running CKEditor AI on our cloud, including the base URLs you call, where your data is processed and stored, what we operate, and the limits we apply.

On SaaS, we run CKEditor AI on our infrastructure and call model providers through our accounts. You do not provision servers, hold provider accounts, or upgrade anything when models change.

If your documents cannot leave your network, or you need to pick the models yourself, see [On-Premises](on-premises.md). For how the two variants differ across CKEditor Cloud Services, in updates, support, and regions, see [SaaS vs. On-Premises](../saas-vs-on-premises.md).

<a id="base-urls">

## Base URLs

Each region has its own base URL. Use the base URL for the region of your environment:

| Region | Base URL                   |
| ------ | -------------------------- |
| US     | `https://ai.cke-cs.com`    |
| EU     | `https://ai.cke-cs-eu.com` |

The paths are the same in both regions. The Customer Portal lists each environment with its region. See [Cloud region](../../developer-resources/environments/environments-management.md#cloud-region). See the [REST API](rest-api.md) for endpoint schemas, error codes, and the OpenAPI specification.

<a id="regions-and-data-processing">

## Regions and data processing

Your environment’s data stays in its region, US or EU. See [Cloud region](../saas-vs-on-premises.md#cloud-region) for multi-region support and for changing the region.

The region sets where your data is stored. Prompts and their attachments go to model providers in the US from both regions. See [Security & compliance](security-and-compliance.md) for what is stored, for how long, and which providers can receive it.

<a id="what-saas-handles">

## What SaaS handles

On SaaS, we handle the following:

* **Infrastructure:** we run and scale the service in your environment’s region.
* **Model provider accounts:** calls to OpenAI, Anthropic, and Google go through our accounts and keys, with no provider contract on your side. See [Models](models.md) for the list.
* **Upgrades:** you get new service versions and models with nothing to deploy on your side. See [Versioning](rest-api.md#versioning) for how existing calls keep working while you migrate.
* **Encryption:** we encrypt the content the service stores and manage the keys. See [Encryption](security-and-compliance.md#encryption) for what is covered.
* **Moderation:** content moderation runs in every SaaS environment. You cannot turn it off. See [Content moderation](security-and-compliance.md#content-moderation) for what it screens.
* **Monitoring:** the [Cloud Services status page](https://status.ckeditor.com/) shows current status, uptime, planned maintenance, and past incidents. You can subscribe to notifications.

<a id="environments-management">

## Environments management

Each environment is a separate tenant. It has its own access key, its own tokens, and its own encryption key. A development environment cannot read or change production data.

Create environments under **Cloud environments** in the [Customer Portal](https://portal.ckeditor.com). The same page holds the access credentials for each one.

<a id="limits">

## Limits

On SaaS, we apply rate limits on requests and tokens per minute, and limits on the size and number of files you attach. Each model also has its own context limits. A request over a rate limit gets a 429 response. Wait, then send it again. See [Limits](rest-api.md#limits) on the REST API page for the values.

Hooks, your own model providers, and MCP servers defined in the deployment configuration need an on-premises deployment. See [Features that need an on-premises deployment](on-premises.md#features-that-need-an-on-premises-deployment).

<a id="next-steps">

## Next steps

* **[Quick start](quick-start.md)** makes a first call with curl.
* **[Authentication](authentication.md)** covers the token endpoint you need in production.
* **[Security & compliance](security-and-compliance.md)** lists what is stored, for how long, and which providers receive it.
* **[On-Premises](on-premises.md)** covers running the service in your own network instead.

---

Full index of the Cloud Services documentation: [llms.txt](../../../llms.txt)
