Platform · Deployment

Run it whereyour data lives.

One containerized platform — managed cloud, your cloud, hybrid, self-hosted or air-gapped. Same artifacts, same governance, every mode.

kubernetes-native · governed by construction

In regulated work, where the software runs is a governance decision — not an ops afterthought.

FlowX.AI is container-native from the ground up, so the artifacts that run on our cloud are the same ones that run in your Kubernetes cluster or on an air-gapped rack. Identity, governance and data residency come along for the ride — you choose the boundary, not a different product.

One platform · control plane + data plane · Helm-delivered
Deployment models

Five ways to run it.

From a vendor-operated SaaS to a fully isolated air-gapped install — the same platform, only the boundary and who operates it change.

SaaS

Managed SaaS

FlowX.AI operates the environment — releases, patching, monitoring and SLAs. Runs in our AWS EU region with tenant isolation. The fastest path to a governed agent in production.

BYOC

Your own cloud

Deploy into your AWS EKS, Azure AKS or Google GKE account with our Helm charts. Your VPC, your keys, your SIEM and pipelines — our platform and upgrades.

Hybrid

Hybrid

A central control plane for governance and lifecycle, with data planes running in your VPCs or datacenters — so process payloads stay local while management stays central.

On-prem

Self-hosted

The full platform inside your perimeter on Red Hat OpenShift or upstream Kubernetes — dependencies in-cluster or pointed at your managed services. You control logs, backups and retention.

Air-gap

Air-gapped

Fully isolated, no external network access. All images and charts served from local mirrors; telemetry stays inside the boundary. OpenShift-recommended for high-assurance regulated estates.

Architecture

Control plane, data plane.

A decoupled architecture is what makes every topology the same platform: governance stays central, execution runs where the data must — connected by one event-driven backbone.

Central

Control plane

Configuration, governance and application lifecycle — OIDC-integrated, promoted across Dev/UAT/Prod.

  • Designer
  • Admin
  • Runtime Manager
  • Integration Designer
  • Audit UI
Per-site

Data plane

Execution runs where the business data lives; process payloads and documents stay in the local stores.

  • Engine
  • Advancing Controller
  • Events Gateway
  • Connectors
  • RDBMS · Mongo · Redis · S3
Backbone

Streaming & telemetry

An event-driven Kafka backbone with configurable observability — sensitive payloads can be suppressed from any central forwarding.

  • Kafka
  • OpenTelemetry
  • Prometheus / Grafana
  • ELK / Loki
Same in every mode

What never changes.

Whichever boundary you pick, these hold — so a workload can move from managed to self-hosted without a rewrite.

Portable

Container-native

Microservices shipped as container images and installed via Helm charts — the same artifacts run on our cloud, yours, OpenShift, or an air-gapped rack.

Anywhere

Cloud & on-prem

Any Kubernetes distribution: AWS EKS, Azure AKS, Google GKE, or Red Hat OpenShift (recommended for regulated on-prem and air-gapped).

Identity

One identity model

OIDC / Keycloak SSO, RBAC and workspace isolation behave the same everywhere — no bespoke auth per environment.

Resilient

HA & scale by default

Multiple pod replicas, HPA autoscaling, Kafka and database replication, multi-AZ or multi-DC spread for DR — built on Kubernetes primitives.

GitOps

Pipelines & upgrades

GitOps (ArgoCD) promotion, two major releases a year plus minors and hotfixes, each with release notes and SBOMs, applied through the same Helm process.

Residency

Your data residency

Pin traces, records and knowledge bases to a region or keep them entirely on-prem. Governance travels with the deployment — compliance follows the data, not the vendor.

By environment

Pick your boundary.

CapabilityManaged SaaSYour cloudHybridSelf-hosted
Who operates itFlowX.AIYouSharedYou
Data residencyAWS EUYour regionLocal data planeYour perimeter
External networkManagedYour VPCYour VPCAir-gap capable
DependenciesManagedIn-cluster or managedLocal per-siteIn-cluster / mirrored
Fastest to productionYes

Read more: Security & Compliance — the controls underneath →

Next

Bring yourconstraints.

Tell us your data-residency and network requirements and we'll show the platform running inside them — managed, in your cloud, or air-gapped.