Skip to main content

  1. Agentycs
  2. Solutions
  3. Sovereign AI platform

Sovereign AI platform

Own the entire AI stack, from the accelerators up to the applications, without giving anyone else custody of your data.

Assembled capability, borrowed control #

Most organisations reach advanced AI by assembling it from other people's services: a model API here, a vector database there, a managed warehouse, a hosting platform, a build system. Each piece is a separate contract, a separate identity system and a separate place your data comes to rest.

The result works right up until it matters. Nobody can say precisely where an answer came from, which system touched the data on the way, or what happens the day a supplier changes its terms, its region or its pricing.

What that costs you

  • Data has to leave your estate to reach a model, and you cannot prove what happened to it there.
  • Identity, permissions and audit are re-implemented differently in every tool, so no single answer is authoritative.
  • Capability is only available where your suppliers choose to operate.
  • Removing one vendor means rebuilding the stack around it.

Sovereignty is not a setting. It is the accumulated effect of every layer resolving inside your boundary.

One platform that carries the whole stack #

Agentycs installs into a cluster you control and brings every layer with it: a lakehouse for your data, a serving plane for your models, a runtime for your applications, an autonomous software factory, the networking between sites and the servers underneath. There is no hidden hop to somebody else's region.

Because it is one platform rather than an integration, identity, tenancy and authorisation resolve through the same audited decision everywhere — the same rule enforced whether a request arrives from a browser, an application, an agent or a SQL client.

Platform Foundation
Identity, authorisation, the application runtime, durable workflows, the database and observability that everything else stands on.
Atom
Your data and intelligence lakehouse: documents, tables and federated external systems as one queryable surface.
Anima
Model serving and inference on your own accelerators, behind one stable interface.
Apex
Purpose-built AI servers across the whole range, from datacentre racks down to a backpack-sized micro server at an air-gapped site.
Cloud Mesh
Sovereign ingress, DNS and zero-trust networking, so you do not depend on an external edge provider.

What owning it actually gives you #

Four properties, each of which is only true because the layer underneath it is also true.

Who you are, and what you may see

One identity and one authorisation decision, whichever door the request arrived by.

One identity, one decision

Federate the OIDC provider you already run — Microsoft Entra, a Google directory or your own — and keep membership in step through SCIM directory sync. Every privileged read or action then resolves through a single audited authorisation decision rather than a per-tool access check.

Tenancy the client cannot assert

Every service derives tenant scope server-side from validated session or token state, never from a header, hostname or hint, with row-level security beneath shared services so even internal components cannot read across the boundary.

Where the models and the data rest

Nothing has to leave the boundary for the platform to work, and you choose the ground it rests on.

No external model host in the path

Models are imported once into your own registry and served from your own content-addressed weight store, so inference keeps working with the internet unplugged.

Your storage, or ours

Datasets rest on the platform's S3-compatible sovereign store by default, or on your own S3-compatible backend. Where data lives is a decision you make per tenant.

How it is operated

The platform is declared rather than administered, and its secrets go through one door.

One audited doorway to every secret

Credentials are held in an encrypted store of record and brokered through a single audited gateway with per-tenant access and rate limits, routed to the cluster vault or to your own external vault.

Declarative operations

The platform is described as Kubernetes custom resources and reconciled by an operator. You declare the state you want; the platform converges to it and reports when it has.

What you can see, and what you could leave with

An exit that depends on our goodwill is not an exit. It has to be a property of the interfaces.

Observability as part of the product

Metrics, dashboards, alerts, distributed traces and continuous network probing ship with the platform, so degradation is visible before it becomes an outage.

Open at every interface

PostgreSQL wire protocol, Arrow Flight SQL, S3-compatible storage, OIDC, SCIM, MCP and Kubernetes. The interfaces you build against are standards, which is what makes an exit strategy real.

Choose the boundary, then choose the ground #

The same platform runs across every pattern, so the deployment decision is about your mandate rather than about which features you keep.

Compare every deployment pattern

Managed sovereign cloud
We operate it; you hold the boundary and the data.
Private cloud
Your cloud account, your network, your keys.
On-premises
Your datacentre, your hardware, your operators.
Air-gapped
No route to the internet, and nothing that needs one.
Multi-site
Geographically distributed for resilience and locality.

Start with your boundary

Bring the constraint that makes public AI services unusable for you — a jurisdiction, a classification, a regulator, an air gap — and we will map what the platform looks like inside it.