Managed sovereign cloud
We run the platform. You keep the authority over identity, keys and data.
What it is #
A managed sovereign cloud is a platform instance that we run on your behalf. Your workloads land in your own tenant, on accelerators we operate, in a region you name, and every service in the path enforces that tenant boundary server-side rather than trusting the caller to declare it.
Sovereign is doing real work in that sentence. Models are imported once into the private model hub and served from platform-owned object storage, so inference has no runtime dependency on an external model host. Networking, DNS and public routing come from Cloud Mesh. Nothing in the serving path belongs to a provider you did not choose.
Who it is for
- You want the platform running in weeks rather than after a hardware programme.
- You need a named region and a named operator, not an opaque global cloud.
- You want to sign in with your existing identity provider and keep key custody.
- Your capacity needs will grow, and you would rather someone else absorbed that.
We run the machines. You keep the authority. Those are two different questions and they get two different answers.
What you get #
The whole platform runs here. These are the parts this pattern changes the shape of.
The whole platform, on day one #
Atom's lakehouse and hybrid search, Anima's model serving, the app runtime and its REST and MCP surfaces, durable workflows, and the Agent² Software Factory. Nothing is held back for a larger tier.
Your identity, your tenants #
Federate your own OIDC provider, keep membership in step over SCIM, and let one authorisation decision cover every request from the browser, an API token or an agent.
Accelerators sized to the work #
Apex servers we operate and expand, with architecture-aware placement so each model runs in the numeric format its hardware actually accelerates.
Health you can see #
Metrics, traces, dashboards and alerts ship with the platform, and per-tenant usage rollups show which models cost what.
The operating model #
Nobody should discover who owns a failure while it is happening. This split is explicit before anything is signed, and it is the part of a deployment decision that outlives the architecture.
- We operate
- Accelerators, the cluster, platform reconciliation, upgrades, backups and the on-call rota behind the platform itself.
- You operate
- Your tenants and their users, your data and datasets, the apps you ship and the models you choose to deploy.
- You keep
- Identity federation, key custody, tenant policy, and the decision about whether any external model provider may ever serve one of your requests.
- We agree together
- The region, the capacity envelope, change windows and the escalation path.