Managed SaaS
FlowX.AI operates the environment — releases, patching, monitoring and SLAs. Runs in our AWS EU region with tenant isolation. The fastest path to a governed agent in production.
Platform · Deployment
One containerized platform — managed cloud, your cloud, hybrid, self-hosted or air-gapped. Same artifacts, same governance, every mode.
kubernetes-native · governed by construction
In regulated work, where the software runs is a governance decision — not an ops afterthought.
FlowX.AI is container-native from the ground up, so the artifacts that run on our cloud are the same ones that run in your Kubernetes cluster or on an air-gapped rack. Identity, governance and data residency come along for the ride — you choose the boundary, not a different product.
One platform · control plane + data plane · Helm-deliveredFrom a vendor-operated SaaS to a fully isolated air-gapped install — the same platform, only the boundary and who operates it change.
FlowX.AI operates the environment — releases, patching, monitoring and SLAs. Runs in our AWS EU region with tenant isolation. The fastest path to a governed agent in production.
Deploy into your AWS EKS, Azure AKS or Google GKE account with our Helm charts. Your VPC, your keys, your SIEM and pipelines — our platform and upgrades.
A central control plane for governance and lifecycle, with data planes running in your VPCs or datacenters — so process payloads stay local while management stays central.
The full platform inside your perimeter on Red Hat OpenShift or upstream Kubernetes — dependencies in-cluster or pointed at your managed services. You control logs, backups and retention.
Fully isolated, no external network access. All images and charts served from local mirrors; telemetry stays inside the boundary. OpenShift-recommended for high-assurance regulated estates.
A decoupled architecture is what makes every topology the same platform: governance stays central, execution runs where the data must — connected by one event-driven backbone.
Configuration, governance and application lifecycle — OIDC-integrated, promoted across Dev/UAT/Prod.
Execution runs where the business data lives; process payloads and documents stay in the local stores.
An event-driven Kafka backbone with configurable observability — sensitive payloads can be suppressed from any central forwarding.
Whichever boundary you pick, these hold — so a workload can move from managed to self-hosted without a rewrite.
Microservices shipped as container images and installed via Helm charts — the same artifacts run on our cloud, yours, OpenShift, or an air-gapped rack.
Any Kubernetes distribution: AWS EKS, Azure AKS, Google GKE, or Red Hat OpenShift (recommended for regulated on-prem and air-gapped).
OIDC / Keycloak SSO, RBAC and workspace isolation behave the same everywhere — no bespoke auth per environment.
Multiple pod replicas, HPA autoscaling, Kafka and database replication, multi-AZ or multi-DC spread for DR — built on Kubernetes primitives.
GitOps (ArgoCD) promotion, two major releases a year plus minors and hotfixes, each with release notes and SBOMs, applied through the same Helm process.
Pin traces, records and knowledge bases to a region or keep them entirely on-prem. Governance travels with the deployment — compliance follows the data, not the vendor.
| Capability | Managed SaaS | Your cloud | Hybrid | Self-hosted |
|---|---|---|---|---|
| Who operates it | FlowX.AI | You | Shared | You |
| Data residency | AWS EU | Your region | Local data plane | Your perimeter |
| External network | Managed | Your VPC | Your VPC | Air-gap capable |
| Dependencies | Managed | In-cluster or managed | Local per-site | In-cluster / mirrored |
| Fastest to production | Yes | — | — | — |
Read more: Security & Compliance — the controls underneath →
Tell us your data-residency and network requirements and we'll show the platform running inside them — managed, in your cloud, or air-gapped.