Your model. Your keys.
The Boreon MCP Layer lets you choose the model for every task over Tableau Server or Tableau Cloud. Keys are encrypted at rest, every change is audited, and self-hosted installs keep the keys entirely yours.
An example routing
- Chat
- Swiss-hosted open model
- Drafts
- Claude Sonnet
- Escalation
- Claude Opus
- Classification
- OpenAI GPT
Keys encrypted at rest · every change audited
The model you choose, per task
The Boreon MCP Layer holds a slot for each provider and routes every task to the model you pick.
- Infomaniak AISwiss · the defaultOpen models such as Qwen and Gemma, hosted in Geneva.
- AnthropicClaudeClaude Sonnet, Opus or Haiku, chosen per task.
- OpenAIGPTGPT models, through the OpenAI-compatible slot.
- Any compatible endpointOpenAI-compatibleAny OpenAI-compatible https endpoint, through the same slot.

Every task on its own model
Chat, drafts, escalation and classification each run on the model you choose, over Tableau Server or Tableau Cloud.
Each route is yours to set, task by task, over Tableau Server or Tableau Cloud.
Swiss-hosted open models are the default. Claude and any OpenAI-compatible endpoint are there for any task you give them.
Your Tableau. Your rules.
Run the Boreon MCP Layer on your own infrastructure or hosted in Switzerland, with the controls your security team asks for.
- Self-hosted or Swiss-hosted. A signed offline bundle for your own cloud, or hosted by us in Switzerland.
- Read-only by default. Tableau Server or Tableau Cloud is read through Tableau’s own APIs, read-only. The one write is a workbook you ask to publish.
- SSO, MFA and audit. Entra ID or any OIDC provider, with every action on the record.
- A WAF at the front door. OWASP Coraza with the Core Rule Set.

Where it runs, side by side
The same Boreon MCP Layer, on your infrastructure or ours in Switzerland.
| Self-hosted | Swiss-hosted | |
|---|---|---|
| Where it runs | On your own infrastructure, from a signed offline bundle | Hosted by Boreon in Switzerland |
| Model keys | Entirely yours | Encrypted at rest, with every change audited |
| Sign-in | Entra ID or any OIDC provider, with MFA | Entra ID or any OIDC provider, with MFA |
| Access to Tableau | Read-only by default | Read-only by default |
| Front door | A WAF with OWASP Coraza and the Core Rule Set | A WAF with OWASP Coraza and the Core Rule Set |
Questions about models and keys
What security and platform teams ask.
Which model is the default?
Can each task use a different model?
Where are the keys kept?
Does the model change what it can read?
How do people sign in?
Ask your own Tableau, live.
Bring one question from your Tableau Server or Tableau Cloud site. The Boreon MCP Layer will answer it in line, on the model you choose.