
CLOUD
AgentX Cloud - all 5 layers managed
Agent · Knowledge · Execution · Deployment · Enterprise
CUSTOMER PERIMETER
Browser · API client
Fastest to go live. Managed by us.
HYBRID
Control plane (AgentX)
Data plane (Customer VPC)
Agent · Knowledge · Execution
CUSTOMER PERIMETER
VPC · IAM · KMS
Data stays. Processing moves. Best of both.
ON-PREM
CUSTOMER PERIMETER · DATACENTER / AIR-GAPPED
All 5 layers in customer perimeter
Agent · Knowledge · Execution · Deployment · Enterprise
Nothing leaves your network.
SHARED RESPONSIBILITY
PLATFORM
WORKSPACE
SECURITY
BOUNDARIES IN MSA
The shared responsibility model is part of the master service agreement. Not a marketing summary - a contractual division.
Boundary changes are versioned
If responsibilities shift (e.g., customer takes over patching on hybrid), the change is documented and signed. No drift.
Incident escalation routes follow the boundary
Platform incidents follow AgentX runbooks. Operational incidents follow customer runbooks. Co-managed incidents have joint runbooks.
CLOUD
Regions
US (us-east-1, us-west-2), EU (eu-west-1, eu-central-1), APAC (ap-southeast-1)
Data residency
EU-only or US-only on Cloud tier (Enterprise can pin specific regions)
Encryption
EU-only or US-only on Cloud tier (Enterprise can pin specific regions)
High availability
TLS 1.3 in transit, AES-256 at rest, AWS KMS for key management
Backups
Automated daily backups, retained per workspace policy
Scaling
Automatic horizontal scaling based on load
Updates
Continuous deployment by AgentX with no customer action required
Monitoring
24/7 platform monitoring with on-call rotation
✓ Customer doesn’t require data to stay within own infrastructure
✓ Standard cloud SaaS procurement model is acceptable
✓ IT team wants zero server management overhead
✓ Fastest time-to-deploy - live in days, not weeks
INTEGRATIONS
ERP
Systems
SAP, Oracle, NetSuite, Microsoft Dynamics, Sage, Infor, custom in-house
Mechanism
Native MCP servers where available; API integration; database read access for read-heavy workflows
Common patterns
Document posting, GL coding, vendor master sync, invoice routing
CRM
Systems
Salesforce, HubSpot, Microsoft Dynamics, Pipedrive
Mechanism
MCP servers; OAuth-based API integration
Common patterns
Lead routing, customer data enrichment, account context for support agents
HELPDESK
Systems
Zendesk, Intercom, Freshdesk, HubSpot Service
Mechanism
API integration; webhook triggers for inbound; OAuth-based write access
Common patterns
Ticket classification, agent-drafted responses, escalation routing, knowledge retrieval
DOCUMENT SOURCES
Systems
Shared mailboxes (IMAP/Exchange), SFTP, vendor portals, scanners, document APIs
Mechanism
Direct connection where possible; polling for legacy systems; webhook for modern systems
Common patterns
Invoice intake, contract intake, document classification, OCR + structured extraction
STORAGE
Systems
SharePoint, Google Drive, Microsoft OneDrive, AWS S3, on-prem file shares (SMB/NFS)
Mechanism
Native connectors; OAuth for cloud; SMB/NFS for on-prem
Common patterns
Knowledge base sourcing, document archive, audit log export
COMMUNICATION
Systems
Slack, Microsoft Teams, WhatsApp Business, email (SMTP / Exchange), voice (Twilio, others)
Mechanism
Native channel apps; SMTP for email; webhook-based for custom platforms
Common patterns
HITL approval queues, customer-facing chat, escalation notifications, internal Q&A
✓ 1,000+ pre-built integrations via the MCP marketplace
✓ Custom integrations built during Stage 1 scope if neede
✓ Integration credentials managed in workspace credential vault - never exposed to agent context
DATA RESIDENCY
Data class
Cloud
Hybrid
On-Premise
Conversation history
AgentX region
Customer VPC
Customer
Knowledge base content
AgentX region
Customer VPC
Customer
Agent configuration
AgentX region
Customer VPC
Customer
Workspace metadata
AgentX region
Customer VPC (primary)
Customer
Audit logs
AgentX region
Customer VPC
Customer
Test datasets
AgentX region
Customer VPC
Customer
Eval results
AgentX region
Customer VPC
Customer
Embeddings
AgentX region
Customer VPC
Self-hosted
LLM provider data
Provider region
Provider/Customer
Customer
Integration credentials
AgentX vault
Customer vault
Customer vault
✓ EU residency available on Cloud (EU regions only)
✓ Full customer-controlled residency on Hybrid
✓ Complete on-prem residency on On-Premise
✓ LLM provider routing can be pinned to specific regions per provider (Anthropic EU, OpenAI EU, etc.)
NETWORK
Cloud - Network from customer side
INBOUND (from customer)
HTTPS (443) to AgentX endpoint
WebSocket (443) for streaming connections
OUTBOUND (from agentx to customer
HTTPS to customer integration endpoints (configurable)
Webhook callbacks (configurable, optional)
CONNECTIVITY OPTIONS
Public HTTPS (default)
AWS PrivateLink / Azure Private Endpoint (on request)
IP allowlist available
Hybrid
INBOUND (to customer VPC)
No inbound ports required from AgentX
All traffic is customer-to-endpoint
OUTBOUND (from customer VPC)
HTTPS 443 to api.agentx.ai (control plane)
HTTPS 443 to LLM provider (customer-selected)
All outbound via customer-controlled egress
CONTROL CHANNEL
Mutually authenticated TLS 1.3
Signed JWT payloads; replay protection
Hostname: control.agentx.ai (single FQDN)
On-Premise
INBOUND
No inbound from AgentX - fully air-gapped supported
Client access via internal network only
OUTBOUND
None required (air-gapped default)
Optional: HTTPS 443 to on-prem LLM endpoint
Optional: telemetry opt-in (specific FQDN provided)
UPDATE DELIVERY
Signed tarball via secure file transfer
SHA-256 checksum + GPG signature on every package
Customer applies; rollback supported
OPERATIONS
Operation
Cloud
Hybrid
On-Premise
Initial install
Security patches
Scaling
Monitoring
Backups
Disaster recovery
SLA & SUPPORT
What we commit to (Enterprise tier)
What support looks like
EXIT
DATA RETURN
CONFIGURATION EXPORT
TRANSITION SUPPORT
CONTRACT TERMS
