Enterprise · Private Cloud

Your cloud. Our software.
Zero compromise.

AIRMY Private Cloud deploys the full platform stack into your own AWS, GCP, or Azure VPC — your data never crosses your network perimeter.

3

Cloud Providers

AWS · GCP · Azure

4

Week Deployment

Design to production

0

Shared Resources

Fully single-tenant

15

Deployment Regions

Across 3 clouds

What is AIRMY Private Cloud?

AIRMY Private Cloud is a dedicated, single-tenant deployment of the AIRMY platform into your own cloud account. Unlike shared SaaS, every compute instance, storage volume, and network resource is provisioned exclusively for your organisation.

AIRMY operates the software. You own the infrastructure and the data. Our management plane connects to your deployment over a narrow, auditable control channel — the only traffic that crosses your perimeter. All agent inference, data processing, and logging happen entirely within your VPC.

You can inspect and audit every resource we provision. Our Terraform modules are open and reviewed with you before any infrastructure is created. If you want to revoke our management access, you can — your deployment continues to operate independently.

  • Data never leaves your network perimeter
  • Contractual data residency guarantee
  • Full resource transparency and audit access
  • Bring your own KMS key — AIRMY never sees your key material
private-cloud.architectureDIAGRAM
Your Application
VPC Peering / PrivateLink

/ Your Cloud Account VPC

Agent Runtime Cluster
Orchestration Engine
Audit Log Store
Policy Engine
Customer-Managed KMS
Your key · AIRMY never has access
control plane only · signed · auditable

/ AIRMY Management Plane (outside VPC)

Platform Updates · Health Monitoring · Config Sync

Deploy anywhere your team runs.

Native integrations with the leading cloud providers using their managed Kubernetes services and infrastructure-as-code tooling.

AWS

Amazon Web Services

Supported Regions

us-east-1us-west-2eu-west-1eu-central-1ap-southeast-1ap-northeast-1ca-central-1sa-east-1ap-south-1me-south-1

Deployment: CloudFormation + Terraform

Orchestration: Amazon EKS

Request deployment

Google Cloud

Google Cloud Platform

Supported Regions

us-central1us-east4europe-west1europe-west4asia-southeast1asia-northeast1australia-southeast1northamerica-northeast1

Deployment: Terraform

Orchestration: Google GKE

Request deployment

Azure

Microsoft Azure

Supported Regions

eastuswestus2westeuropenortheuropesoutheastasiaaustraliaeastcanadacentral

Deployment: ARM templates + Terraform

Orchestration: Azure AKS

Request deployment

Everything included.

Private Cloud is not a stripped-down offering. You get the full platform with additional capabilities only possible in a dedicated deployment.

Complete Network Isolation

No traffic ever leaves your VPC boundary. Agent inference, storage, and logging are entirely within your network. Outbound connections from the control plane are limited to signed, auditable management calls.

Customer-Managed Encryption Keys

Bring your own KMS key (AWS KMS, GCP Cloud KMS, Azure Key Vault). All data encrypted with your key. AIRMY never has access to your key material. Key rotation is fully automated.

Data Residency Guarantee

Contractual guarantee that Customer Data is processed and stored exclusively in your designated region. Certifiable for GDPR, Swiss DPA, and other data localisation requirements.

Dedicated Compute

Dedicated node pools sized to your workload. No noisy-neighbour effects. You can inspect and audit every compute resource in your account.

Custom Domain & Certificates

Deploy under your own domain (e.g. agents.yourdomain.com). Bring your own TLS certificates or use Let's Encrypt via cert-manager. Fully transparent to your users.

VPC Peering & PrivateLink

Connect your applications to AIRMY Private Cloud over VPC peering or AWS PrivateLink / GCP Private Service Connect / Azure Private Link — no traffic over the public internet.

Production in 4 weeks.

Our solutions engineering team guides every step. Nothing is deployed without your review and approval.

W1

Design & IAM

Our solutions engineering team reviews your cloud account setup, defines IAM roles, and provides Terraform modules. You grant deployment permissions scoped to minimum privilege.

W2

Infrastructure Provisioning

AIRMY Terraform modules provision VPC, subnets, EKS/GKE/AKS cluster, storage, and KMS configuration. You review and approve every resource before creation.

W3

Platform Deployment

The AIRMY platform stack is deployed: agent runtime, orchestration engine, policy engine, audit log store, and management plane connector. SSO and RBAC configured.

W4

Testing & Handover

End-to-end validation, load testing, and runbook review. Your team completes onboarding with a dedicated solutions engineer. Production cutover.

Shared SaaS vs Private Cloud.

Feature comparison

FeatureShared SaaSPrivate Cloud
Data locationAIRMY-managed regionsYour designated region
Compute sharingMulti-tenantSingle-tenant, dedicated
Encryption keysAIRMY-managedCustomer-managed (BYOK)
Network boundaryShared VPCYour VPC, no shared resources
Custom domainYes (your domain)
Compliance certsShared SOC 2 / ISO certDedicated scope available
Deployment modelInstant, self-serve4-week guided deployment
SupportStandard / Business24/7 + dedicated CSM + SRE

Ready for a dedicated deployment?

Our solutions engineering team will design a Private Cloud architecture that fits your security, compliance, and performance requirements.