Skip to content

Deployment

Your environment. Your network. Your rules.

Three deployment models. Same platform, same UI, same governance, same evaluation. Cloud when speed matters. Hybrid when sensitive data has to stay put. On-premise when nothing leaves your perimeter - and not as a six-month special-case project, but as a documented deployment path with the same operational maturity as cloud.

01Cloud

AgentX Cloud - all 5 layers managed

Agent · Knowledge · Execution · Deployment · Enterprise

Customer perimeter

Browser · API client

Fastest to go live. Managed by us.

02Hybrid

Control plane (AgentX) / Data plane (Customer VPC)

Agent · Knowledge · Execution

Customer perimeter

VPC · IAM · KMS

Data stays. Processing moves. Best of both.

03On-prem

All 5 layers in customer perimeter

Agent · Knowledge · Execution · Deployment · Enterprise

Customer perimeter · Datacenter / Air-gapped

Nothing leaves your network.

Shared responsibility

Who manages what - explicitly.

Every deployment model has a different boundary. We document the boundary up front. No surprises during procurement, no ambiguity during incident response, no “I thought you handled that” moments at 2am.

Platform
LayerCloudHybridOn-Premise
Physical infrastructureAgentXCustomerCustomer
Network infrastructureAgentXCustomerCustomer
Operating systemsAgentXCustomerCustomer
Container runtimeAgentXCo-managedCustomer
AgentX platform softwareAgentXAgentX (provided)Customer (applied)
Software upgrades & patchesAgentXAgentX (provided)Customer (applied)
Data planeAgentXCustomerCustomer
Control planeAgentXAgentXCustomer
Monitoring infrastructureAgentXCo-managedCustomer
BackupsAgentXCustomerCustomer
Disaster recoveryAgentXCo-managedCustomer
Workspace
LayerCloudHybridOn-Premise
Workspace configurationCustomerCustomerCustomer
Agent design and configurationCustomerCustomerCustomer
Knowledge base contentCustomerCustomerCustomer
Integration credentialsCustomerCustomerCustomer
RBAC users and permissionsCustomerCustomerCustomer
Business dataCustomerCustomerCustomer
HITL workflow designCustomerCustomerCustomer
SSO / IdP integrationCustomerCustomerCustomer
Security
LayerCloudHybridOn-Premise
Compute & container runtimeAgentXAgentX (provided)Customer (applied)
Network infrastructureCustomerCustomerCustomer
Data-plane nodesAgentXCo-managedCustomer + AgentX
Control-plane nodesCustomerCustomerCustomer

Boundaries in MSA

The shared responsibility model is part of the master service agreement. Not a marketing summary - a contractual division.

Boundary changes are versioned

If responsibilities shift (e.g., customer takes over patching on hybrid), the change is documented and signed. No drift.

Incident escalation routes follow the boundary

Platform incidents follow AgentX runbooks. Operational incidents follow customer runbooks. Co-managed incidents have joint runbooks.

Cloud

Managed by us. Fastest path to production.

For most teams, cloud is the right starting point. We operate the platform on AWS, multi-region, with operational controls and monitoring in place. Your team manages the workspace, agents, integrations, and business data. You don’t manage servers, patches, scaling, or backups.

Cloud is the right fit when

  • Customer doesn’t require data to stay within own infrastructure
  • Standard cloud SaaS procurement model is acceptable
  • IT team wants zero server management overhead
  • Fastest time-to-deploy - live in days, not weeks

Security controls for cloud deployment detailed in Security

Regions
US (us-east-1, us-west-2), EU (eu-west-1, eu-central-1), APAC (ap-southeast-1)
Data residency
EU-only or US-only on Cloud tier (Enterprise can pin specific regions)
Encryption
TLS 1.3 in transit, AES-256 at rest, AWS KMS for key management
Backups
Automated daily backups, retained per workspace policy
Scaling
Automatic horizontal scaling based on load
Updates
Continuous deployment by AgentX with no customer action required
Monitoring
24/7 platform monitoring with on-call rotation
Data plane
Customer VPC - all agent data, knowledge bases, and run history stay in your environment
Control plane
AgentX SaaS - orchestration, scheduling, and workspace management
Customer network
Outbound HTTPS only; mutually authenticated; signed payloads
Customer infrastructure required
Kubernetes cluster in your VPC; minimum 4 nodes, sizing guide provided
Network requirement
Outbound 443 to AgentX endpoints only; no inbound ports required
LLM provider routing
Direct from your VPC to provider APIs or your private LLM endpoint
Updates
Signed OCI images pulled on schedule; rollback supported
Monitoring
Customer’s existing observability stack (CloudWatch, Datadog, etc.); AgentX exports OpenTelemetry metrics
Support access
Break-glass access via customer-approved session; full audit trail

Hybrid

Your data plane. Our control plane.

Hybrid is for organizations where sensitive data can’t leave their infrastructure - but full on-premise operations would mean owning the entire runtime stack. We split the deployment: the agent runtime, knowledge base, and execution layer live in your VPC. The control plane (workspace management, evaluation orchestration, version management) is operated by us, communicating with your runtime over signed, encrypted channels.

Hybrid is the right fit when

  • Data residency requirements mandate data stays in own environment
  • Customer has cloud infrastructure team or willing partner
  • Full on-prem isn’t required (some external connections acceptable)
  • Customer wants control over patching cadence

Platform architecture detail here

On-premise

Nothing leaves your perimeter.

On-premise isn’t a marketing checkbox. It’s a documented deployment path with the same operational maturity as cloud. Air-gapped environments supported. Self-hosted LLMs supported. Customer-operated with AgentX providing software packages, runbooks, and escalation support. Required for certain regulated environments - and we support it without making it a six-month project.

On-premise is the right fit when

  • Regulatory requirement that data and processing stay on-prem
  • Air-gapped network requirement
  • Customer has datacenter / private cloud operational maturity
  • Long-term operational independence preferred over managed convenience
Deployment target
Bare-metal, VMware, OpenStack, or air-gapped Kubernetes
Network requirement
No outbound internet required; air-gap mode supported
Compute
Self-managed Kubernetes; bare-metal or VM; full sizing spec provided
Storage
Customer-managed; Postgres + S3-compatible object store required
LLM access
Private LLM endpoints or proxied external APIs; BYOM supported
Upgrades
Customer-controlled; signed OCI images; rollback to prior version supported
Monitoring
Customer-managed; OpenTelemetry export available; no mandatory call-home
Support access
Support tunnels via customer-controlled bastion host; no persistent access
Backups
Customer-managed; snapshot tooling and schedule documentation provided

Integrations

We connect to what you already run.

Every enterprise process automation engagement requires integrating with the systems your team already uses. ERP. CRM. Helpdesk. Document sources. Storage. Communication. We work with what’s already in place - no requirement to migrate to AgentX-preferred tooling.

Full integration catalogue

ERP

Systems
SAP, Oracle, NetSuite, Microsoft Dynamics, Sage, Infor, custom in-house
Mechanism
Native MCP servers where available; API integration; database read access for read-heavy workflows
Common patterns
Document posting, GL coding, vendor master sync, invoice routing

CRM

Systems
Salesforce, HubSpot, Microsoft Dynamics, Pipedrive
Mechanism
MCP servers; OAuth-based API integration
Common patterns
Lead routing, customer data enrichment, account context for support agents

Helpdesk

Systems
Zendesk, Intercom, Freshdesk, HubSpot Service
Mechanism
API integration; webhook triggers for inbound; OAuth-based write access
Common patterns
Ticket classification, agent-drafted responses, escalation routing, knowledge retrieval

Document sources

Systems
Shared mailboxes (IMAP/Exchange), SFTP, vendor portals, scanners, document APIs
Mechanism
Direct connection where possible; polling for legacy systems; webhook for modern systems
Common patterns
Invoice intake, contract intake, document classification, OCR + structured extraction

Storage

Systems
SharePoint, Google Drive, Microsoft OneDrive, AWS S3, on-prem file shares (SMB/NFS)
Mechanism
Native connectors; OAuth for cloud; SMB/NFS for on-prem
Common patterns
Knowledge base sourcing, document archive, audit log export

Communication

Systems
Slack, Microsoft Teams, WhatsApp Business, email (SMTP / Exchange), voice (Twilio, others)
Mechanism
Native channel apps; SMTP for email; webhook-based for custom platforms
Common patterns
HITL approval queues, customer-facing chat, escalation notifications, internal Q&A
  • 1,000+ pre-built integrations via the MCP marketplace
  • Custom integrations built during Stage 1 scope if needed
  • Integration credentials managed in workspace credential vault - never exposed to agent context

Data residency

Where your data lives. Documented.

Data residency requirements are increasingly common - GDPR, DORA, regional regulations, internal data classification policies. The deployment model determines residency options. The deployment plan documents exactly where each data class lives.

Data residency by deployment model
Data classCloudHybridOn-Premise
Conversation historyAgentX regionCustomer VPCCustomer
Knowledge base contentAgentX regionCustomer VPCCustomer
Agent configurationAgentX regionCustomer VPCCustomer
Workspace metadataAgentX regionCustomer VPC (primary)Customer
Audit logsAgentX regionCustomer VPCCustomer
Test datasetsAgentX regionCustomer VPCCustomer
Eval resultsAgentX regionCustomer VPCCustomer
EmbeddingsAgentX regionCustomer VPCSelf-hosted
LLM provider dataProvider regionProvider/CustomerCustomer
Integration credentialsAgentX vaultCustomer vaultCustomer vault
  • EU residency available on Cloud (EU regions only)
  • Full customer-controlled residency on Hybrid
  • Complete on-prem residency on On-Premise
  • LLM provider routing can be pinned to specific regions per provider (Anthropic EU, OpenAI EU, etc.)
AI governance & compliance framework

Network

Network requirements your IT team can verify.

Documented inbound and outbound network requirements per deployment model. No surprises during firewall review. No “it might also need this port” conversations during go-live.

Cloud - Network from customer side

Inbound (from customer)

  • HTTPS (443) to AgentX endpoint
  • WebSocket (443) for streaming connections

Outbound (from AgentX to customer)

  • HTTPS to customer integration endpoints (configurable)
  • Webhook callbacks (configurable, optional)

Connectivity options

  • Public HTTPS (default)
  • AWS PrivateLink / Azure Private Endpoint (on request)
  • IP allowlist available

Hybrid

Inbound (to customer VPC)

  • No inbound ports required from AgentX
  • All traffic is customer-to-endpoint

Outbound (from customer VPC)

  • HTTPS 443 to api.agentx.ai (control plane)
  • HTTPS 443 to LLM provider (customer-selected)
  • All outbound via customer-controlled egress

Control channel

  • Mutually authenticated TLS 1.3
  • Signed JWT payloads; replay protection
  • Hostname: control.agentx.ai (single FQDN)

On-Premise

Inbound

  • No inbound from AgentX - fully air-gapped supported
  • Client access via internal network only

Outbound

  • None required (air-gapped default)
  • Optional: HTTPS 443 to on-prem LLM endpoint
  • Optional: telemetry opt-in (specific FQDN provided)

Update delivery

  • Signed tarball via secure file transfer
  • SHA-256 checksum + GPG signature on every package
  • Customer applies; rollback supported

Operations

Install. Upgrade. Patch. Scale. Monitor.

Day-two operations defined per deployment model. You know what changes, who owns it, and what the escalation path looks like before you go live.

Day-two operations
OperationCloudHybridOn-Premise
Initial installZero-touch; workspace created in <24hAgentX deploys to customer K8s; guided runbookCustomer applies signed package; AgentX support on-call
Platform upgradesAutomatic; maintenance window notified 7 days priorSigned image pull; customer-scheduled; rollback supportedCustomer-applied package; GPG verified; rollback documented
Security patchesAgentX; critical patches <24h, standard 7-day windowAgentX releases patch; customer applies within agreed SLACustomer applies; AgentX provides CVE advisory + patch tarball
ScalingAuto-scaling; no action requiredCustomer scales K8s nodes; AgentX provides sizing guideCustomer provisions hardware per sizing guide
MonitoringAgentX observability stack; customer dashboardCustomer stack; AgentX exports OTel metrics + alertsCustomer stack; diagnostic bundle on request
BackupsAgentX automated; daily snapshot, 30-day retentionCustomer-managed; AgentX provides export toolingCustomer-managed; RPO/RTO TBD with delivery
Disaster recoveryAgentX-managed; RTO/RPO TBD with deliveryCustomer DR plan; AgentX runbook providedCustomer DR plan; offline restore procedure documented
Support accessTAM + SRE on-call; shared Slack channelBreak-glass session; audited; customer-approvedOffline diagnostic bundle; optional VPN session

Signed update packages

You control what runs in your environment

Every update - cloud, hybrid, or on-prem - ships as a signed package. GPG signature and SHA-256 checksum on every release. Verify before you apply.

Documented upgrade paths

No surprise migrations

Every version bump has a documented upgrade path, rollback procedure, and compatibility matrix. We don’t drop breaking changes without a migration guide and a minimum 90-day notice window.

Defined escalation routes

You always know who to call

P1 incidents have a direct pager to the on-call SRE. P2/P3 go through your TAM. Escalation SLAs are documented in the MSA and verified during onboarding.

SLA & support

Commitments documented in the MSA. Not the marketing page.

What we commit to, what support looks like, and what you can hold us to. All in writing before you sign.

What we commit to (Enterprise tier)

Availability
TBD with delivery / legal - documented in MSA before signature
Incident response
P1: 30-min acknowledgement; P2: 4h; P3: next business day
Maintenance windows
7-day advance notice; customer-agreed scheduling for P1 ops
Data export
On-demand export of all customer data in standard formats
Uptime reporting
Monthly report + public status page; historical incident log available
Service credits
Automatic credit for availability breaches; no claim filing required

What support looks like

Named TAM
Dedicated Technical Account Manager from day 1; attends your weekly ops review
Shared Slack channel
Direct line to AgentX engineering during business hours; async coverage outside
SRE on-call
24/7 on-call rotation for P1 incidents; escalation path to engineering lead
Onboarding
Structured 30-day onboarding; includes network validation, runbook walkthrough, and first agent deploy
Quarterly business review
TAM-led QBR; covers platform health, upcoming roadmap, and open items
Security questionnaire support
Direct answers from engineering; no sales filter; response SLA in MSA
Roadmap input
Enterprise customers get direct input into quarterly roadmap; blockers escalated to product

Specific SLA percentages (availability, RTO, RPO) are TBD with delivery and legal, and will be documented in your MSA before signature. Numbers on this page are illustrative of the support model, not contractual commitments until countersigned.

Exit

How you leave. Documented up front.

Exit terms are in the MSA before you sign. We don’t make leaving hard - your data is yours, your configuration is yours, and the transition period is defined.

Data return

All customer data - run history, knowledge bases, embeddings, agent configurations, and audit logs - exported in standard formats (JSON, CSV, Parquet) within 30 days of termination. Secure transfer method agreed in exit plan. AgentX-held copies purged within 30 days of confirmed receipt, with written confirmation.

Configuration export

Agent definitions, workflow configurations, integration mappings, and prompt templates exported as version-controlled YAML/JSON. Compatible with standard workflow tools to reduce re-build effort. API access maintained for 90 days post-termination for migration purposes.

Transition support

90-day transition period (TBD with delivery) included in Enterprise exit terms. TAM remains point of contact through transition. Read-only access to platform maintained during migration window. Architecture documentation and integration specs provided to successor team.

Contract terms

Exit provisions are in the MSA before signature, not negotiated at termination. Data portability, purge timeline, transition period length, and post-termination API access window are all documented. No lock-in clauses, no data hostage provisions.

Ready for the infrastructure conversation?

Bring your IT lead. We’ll bring the architecture diagrams.

A 45-minute call. We’ll walk through which deployment model fits your environment, what the network and integration requirements look like for your specific setup, and what your team would need to provide for hybrid or on-prem. We bring reference architectures. You bring your environment constraints. We match them.

Start your AI automation journey today

Sign up for AgentX and let AI handle your routine tasks - no credit card needed.