VapusData logoVapusData logo

Trust

Deploy anywhere. Trust everywhere.

Run VapusData where your data is allowed to live — our cloud, your cloud, your datacentre, or fully disconnected. Same product, same features, no functionality fork between tiers.

Shared to air-gappedCloud-native & virtualisedYour keys, your network

Deployment

Four ways to run it, one product

The deployment mode changes who operates the plane and where the bytes sit. It does not change what the product does. Pick the mode your regulator, your security review and your platform team can all live with, and move between them later without a migration project.

  • Shared instance

    Operated by
    VapusData
    Data residency
    Our infrastructure, region of your choice
    At the boundary
    The platform runs inside the VapusData boundary. Your workloads and results cross it in both directions over authenticated, encrypted channels.

    Data leaves your network: Yes

  • Dedicated instance

    Operated by
    VapusData, dedicated to one customer
    Data residency
    Our infrastructure, single-tenant, region of your choice
    At the boundary
    One tenant behind the boundary. Bring your own KMS key so the data at rest is encrypted under a key we do not hold alone.

    Data leaves your network: Yes

  • Your cloud

    Operated by
    You, with VapusData support
    Data residency
    Your cloud account, your region, your VPC
    At the boundary
    The target environment sits on your side of the boundary. The only line that crosses carries control-plane management traffic, and it can be routed through your egress proxy.

    Data leaves your network: Yes

  • On-premise & air-gapped

    Operated by
    You
    Data residency
    Your datacentre, your hardware
    At the boundary
    There is no live link. Licensing, upgrades and model artifacts arrive as a signed bundle you import; telemetry stays inside and is exported only if you choose to export it.

    Data leaves your network: No

Shared instance

Fastest path to production

Multi-tenant, multi-cloud, highly available. We run it, you consume it.

Operated by
VapusData
Data residency
Our infrastructure, region of your choice
Best for
Teams that want value this quarter, not next.

Data leaves your network: Yes

Dedicated instance

Single tenant, still managed

Your own isolated instance on VapusData infrastructure — separate compute, separate storage, separate keys — operated and upgraded by us.

Operated by
VapusData, dedicated to one customer
Data residency
Our infrastructure, single-tenant, region of your choice
Best for
Regulated teams that need isolation without running the plane themselves.

Data leaves your network: Yes

Your cloud

Runs in your account, on your network

Installed into your own AWS, Azure or GCP account. Data planes, storage and models stay inside your VPC; only management traffic — licensing, version metadata, health — crosses back to us.

Operated by
You, with VapusData support
Data residency
Your cloud account, your region, your VPC
Best for
Enterprises with an existing cloud landing zone and their own network controls.

Data leaves your network: Yes

On-premise & air-gapped

Nothing leaves the network

Installed in your datacentre, including networks with no route to the internet. Images, charts and model artifacts are delivered as a signed offline bundle and promoted through your own registry.

Operated by
You
Data residency
Your datacentre, your hardware
Best for
Defence, public sector and any workload that cannot egress.

Data leaves your network: No

Form factors

Cloud-native or virtualised — your platform team decides

The same release, packaged two ways. Both take the same configuration, the same upgrade path and the same offline bundle format.

Cloud-native

Kubernetes-native. Helm charts installed through vapusctl, which runs preflight checks first. Runs on EKS, AKS, GKE or any conformant cluster.

  • Kubernetes
  • Helm / vapusctl
  • Artifact Registry
  • Secret Manager
  • Object storage

Virtualised

For estates without Kubernetes. Delivered as VM images for your hypervisor, with the same components and the same upgrade path.

  • VM images
  • Hypervisor of record
  • Local object store
  • Bundled dependencies

Reliability

Instrumented so you can see it, not just be told about it

Every deployment ships the same telemetry surface. In managed modes we watch it; in your cloud and on-premise it is yours, and it points at your collectors rather than ours.

Observability

OpenTelemetry traces, metrics and structured logs from every service, exported to your collector — Prometheus, Grafana, Datadog or the stack you already run.

Health monitoring

Liveness and readiness probes per component, queue depth and model-latency signals, and alert rules shipped with the chart so a fresh install is monitored on day one.

Adaptive scaling

Workers scale on queue depth rather than CPU alone, so a backlog drains instead of timing out. Limits are yours to set in every self-operated mode.

Upgrades and rollback

Versioned releases with a preflight check, a documented rollback path, and the same bundle format whether the cluster is connected or disconnected.

Support

Engineers who have installed it, not a ticket queue

Support is staffed by the people who build and deploy the platform. Response commitments are set in your agreement; the figures below are published once they are contractual rather than aspirational.

Deployment and onboarding
Preflight review of your cluster or hypervisor estate, install session, and a runbook written against your environment rather than a generic one.
Production support
Named channel for incidents, with escalation to the engineer who owns the component. Covers the platform, the connectors and the deployment tooling.
Air-gapped support
Offline diagnostics bundle you inspect before sending, so nothing leaves your network that you have not read. Upgrade bundles are signed and verified in your registry.
Security enquiries
Vulnerability reports, questionnaire responses and architecture review for your security team, handled by the security contact rather than general support.

Security & compliance

What runs where, who can reach it, what is logged

We publish the mechanism rather than a posture. A standard is only listed once we actually meet it, and a mark only appears next to a standard we hold today.

Encryption

In transit and at rest. Bring your own KMS key in dedicated and customer-cloud deployments.

Access control

Role-based access, tenant isolation, full audit trail on every action.

Data residency

Choose the region, or run where there is no region at all.

Secrets

Credentials are held in a secret manager — yours in self-operated modes — and referenced by handle. They are never written into configuration or logs.

Supply chain

Signed images and charts with an SBOM per release, verified before install by vapusctl and again by your registry if you promote through one.

Tenant isolation

Every query, job and agent action is bound to a tenant and a purpose. Cross-tenant reads are not a permission that can be granted.

Certifications

None of the standards below is claimed as held today. Each is listed with its audit under way; the certificate number and audit date are published here, and the mark appears, only once the certificate has been issued and checked against it.

  • ISO 9001:2015 certification mark

    ISO 9001

    Certified

    Quality management system covering the engineering, release and support processes behind the platform.

  • ISO 27001 certification mark

    ISO 27001

    Certified

    Information security management system covering access control, change management and incident response.

  • AICPA SOC 2 service organisation control report mark

    SOC 2 Type II

    Certified

    Controls for security and availability, observed over a period rather than at a point in time.

  • SLSA Level 3 certification mark

    SLSA Level 3

    Certified

    Hardened, source-controlled builds that emit signed provenance for every image, chart and offline bundle, so what you install can be traced back to the commit it was built from.

  • EU GDPR

    Audit in progress

    Assessment of the platform's handling of personal data under the EU General Data Protection Regulation, covering lawful processing, data subject rights and cross-border transfer controls.

  • UK GDPR

    Audit in progress

    Assessment against the UK General Data Protection Regulation and the Data Protection Act 2018, including UK-resident deployment options for personal data.

Controls we help you enforce

These are regulatory regimes our customers operate under. The platform provides controls that support your obligations; compliance remains yours to demonstrate, and these are not certifications held by Anekam Datanet.

GDPR
Controls the platform helps you enforce: consent tracking, data subject requests, retention policy, and a region choice so personal data need not leave the EU.
India DPDP Act 2023
Purpose and consent recorded against each data product, notice and withdrawal flows, and in-country deployment so personal data of data principals stays in India.
HIPAA
Access control, audit logging and encryption for protected health information, with on-premise and air-gapped modes for estates that cannot place PHI in a shared tenancy.
RBI and sectoral data localisation
Deployment in the jurisdiction the regulator requires, including fully disconnected installs where no payload may leave the licensed environment.

Questions

Frequently asked

Can we run VapusData fully air-gapped?
Yes. The on-premise mode supports networks with no route to the internet. Images, Helm charts and model artifacts arrive as a signed offline bundle that you import into your own registry, and vapusctl installs from there. No component requires an outbound call to run.
Where does our data live in each mode?
Shared and dedicated: on VapusData infrastructure, in the region you select. Your cloud: in your own account, region and VPC. On-premise: on your hardware. The mode you choose sets the answer; there is no hidden copy in another tier.
What leaves our network?
In shared and dedicated, your workloads and results cross the boundary because we operate the plane. In your cloud, only control-plane management traffic — licensing, version metadata and health — crosses, and it can be routed through your egress proxy. On-premise and air-gapped, nothing crosses; the link is not there to cross.
Who holds the encryption keys?
In dedicated and customer-cloud deployments you can bring your own KMS key, so data at rest is encrypted under a key you can rotate or revoke. On-premise, the key material never leaves your key manager at all. In the shared instance the keys are managed by VapusData.
How are upgrades delivered in a disconnected environment?
As a versioned, signed bundle containing images, charts and model artifacts. You verify the signature, promote it through your own registry, and vapusctl runs its preflight checks before applying. The rollback path is the previous bundle, which stays in your registry.
What happens to our data if we leave?
Data products, metadata and audit history are exportable in open formats while your agreement is live, and the export is a documented command rather than a support request. In self-operated modes the data is already yours — it never sat with us. Deletion timelines for managed modes are set in the agreement and in the privacy policy.
Do the features differ between deployment modes?
No. The same release runs in every mode. What changes is who operates the plane, where it runs and which external model providers are reachable — an air-gapped install uses the models you host inside the boundary.
Which connectors are available?
Connector coverage is listed on the integrations page, which is the single source of truth for what the platform talks to. The list is identical in every deployment mode, subject to the target being reachable from where you run.

Bring us your constraints

Tell us what your regulator, your network and your security review require, and we will show you which deployment mode meets them — including the one where nothing leaves.

Essential cookies are required for the site to function and cannot be switched off. Everything else is off until you switch it on, and you can change or withdraw your choice at any time from the Cookie settings link in the footer. The Cookie Policy lists the cookies we set and how long each one lasts.

No choice recorded yet