§ Deployment · 02 · VPC

AI Agents Inside Your VPC.

Deploy AI agents in a cloud tenant you own. Data, models, and tools stay in your AWS, GCP, or Azure VPC — egress only when you approve it.

In plain terms: deploy AI agents inside your own AWS, GCP, or Azure cloud tenant.

Your cloud, your rules. The platform runs in a tenant you own — and never leaves it unless you choose to call out.

VPC is the shape for the cloud-native buyer who wants agents in a tenant they control rather than a vendor's. The agent, the secrets broker, the evaluation harness, your data, and your SaaS all run inside your perimeter. Models can run on your compute or be called over a private endpoint — the choice is yours, per agent.

“Data, models, and tools never leave your VPC unless you choose to call out.”

The boundary is yours.

Inside your VPC: the agent, the secrets broker, evaluation and telemetry, your data, and your SaaS. Outside: only the models you choose to call — and only through scoped, brokered access you approve. That is the whole picture: the things that touch your data live behind a boundary you drew.

  • 01

    Egress is an allow-list, not a default

    The agent reaches an external endpoint only when you have blessed it, through a scoped token the broker issues. Nothing phones home.

  • 02

    Bring your committed-use spend

    Compute and any cloud-hosted models count against your existing enterprise agreements and private endpoints.

  • 03

    Tenant isolation, controlled egress

    Containers per run, scoped tokens, only the endpoints you bless. One tenant's data never touches another's — clean by default.

  • 04

    One platform, four shapes

    Start in VPC and move to on-prem or air-gapped later without re-architecting. The agent doesn't care where it runs; your auditor will.

When VPC is the right cut.

VPC suits the cloud-security architect who wants agents inside a tenant they own, the team already running on AWS, GCP, or Azure that wants to use existing commitments, and the regulated buyer whose data-residency posture is satisfied by a tenant they control. If your requirement is physical isolation or no egress path at all, on-premise or air-gapped is the closer fit — and the same platform moves there without a rewrite.

Related deployment shapes.

Questions we hear.

Do you need access to our VPC?
The platform runs in a tenant you own. We forward-deploy into your VPC during deployment and hand over the keys; ongoing operation can be entirely yours under a Standing Account, or we can operate it with you. You control the access model.
Can we use our existing cloud spend commitments?
Yes. Because the platform runs inside your AWS, GCP, or Azure account, compute and any cloud-hosted models you choose count against your existing commitments and enterprise agreements. Bring your committed-use discounts and your private endpoints.
What about models hosted by the cloud provider?
The platform's multi-model abstraction treats provider-hosted models, open-weight models, and sealed local models uniformly. You can call a cloud-hosted model over a private endpoint, run an open model on your own compute, or seal the whole thing — and swap per agent without rewriting it.