AgentX Cloud - all 5 layers managed
Agent · Knowledge · Execution · Deployment · Enterprise
Customer perimeter
Browser · API client
Fastest to go live. Managed by us.
Deployment
Three deployment models. Same platform, same UI, same governance, same evaluation. Cloud when speed matters. Hybrid when sensitive data has to stay put. On-premise when nothing leaves your perimeter - and not as a six-month special-case project, but as a documented deployment path with the same operational maturity as cloud.
AgentX Cloud - all 5 layers managed
Agent · Knowledge · Execution · Deployment · Enterprise
Customer perimeter
Browser · API client
Fastest to go live. Managed by us.
Control plane (AgentX) / Data plane (Customer VPC)
Agent · Knowledge · Execution
Customer perimeter
VPC · IAM · KMS
Data stays. Processing moves. Best of both.
All 5 layers in customer perimeter
Agent · Knowledge · Execution · Deployment · Enterprise
Customer perimeter · Datacenter / Air-gapped
Nothing leaves your network.
Cloud
For most teams, cloud is the right starting point. We operate the platform on AWS, multi-region, with operational controls and monitoring in place. Your team manages the workspace, agents, integrations, and business data. You don’t manage servers, patches, scaling, or backups.
Cloud is the right fit when
Security controls for cloud deployment detailed in Security
Hybrid
Hybrid is for organizations where sensitive data can’t leave their infrastructure - but full on-premise operations would mean owning the entire runtime stack. We split the deployment: the agent runtime, knowledge base, and execution layer live in your VPC. The control plane (workspace management, evaluation orchestration, version management) is operated by us, communicating with your runtime over signed, encrypted channels.
Hybrid is the right fit when
On-premise
On-premise isn’t a marketing checkbox. It’s a documented deployment path with the same operational maturity as cloud. Air-gapped environments supported. Self-hosted LLMs supported. Customer-operated with AgentX providing software packages, runbooks, and escalation support. Required for certain regulated environments - and we support it without making it a six-month project.
On-premise is the right fit when
Integrations
Every enterprise process automation engagement requires integrating with the systems your team already uses. ERP. CRM. Helpdesk. Document sources. Storage. Communication. We work with what’s already in place - no requirement to migrate to AgentX-preferred tooling.
Data residency
Data residency requirements are increasingly common - GDPR, DORA, regional regulations, internal data classification policies. The deployment model determines residency options. The deployment plan documents exactly where each data class lives.
| Data class | Cloud | Hybrid | On-Premise |
|---|---|---|---|
| Conversation history | AgentX region | Customer VPC | Customer |
| Knowledge base content | AgentX region | Customer VPC | Customer |
| Agent configuration | AgentX region | Customer VPC | Customer |
| Workspace metadata | AgentX region | Customer VPC (primary) | Customer |
| Audit logs | AgentX region | Customer VPC | Customer |
| Test datasets | AgentX region | Customer VPC | Customer |
| Eval results | AgentX region | Customer VPC | Customer |
| Embeddings | AgentX region | Customer VPC | Self-hosted |
| LLM provider data | Provider region | Provider/Customer | Customer |
| Integration credentials | AgentX vault | Customer vault | Customer vault |
Network
Documented inbound and outbound network requirements per deployment model. No surprises during firewall review. No “it might also need this port” conversations during go-live.
Inbound (from customer)
Outbound (from AgentX to customer)
Connectivity options
Inbound (to customer VPC)
Outbound (from customer VPC)
Control channel
Inbound
Outbound
Update delivery
Operations
Day-two operations defined per deployment model. You know what changes, who owns it, and what the escalation path looks like before you go live.
| Operation | Cloud | Hybrid | On-Premise |
|---|---|---|---|
| Initial install | Zero-touch; workspace created in <24h | AgentX deploys to customer K8s; guided runbook | Customer applies signed package; AgentX support on-call |
| Platform upgrades | Automatic; maintenance window notified 7 days prior | Signed image pull; customer-scheduled; rollback supported | Customer-applied package; GPG verified; rollback documented |
| Security patches | AgentX; critical patches <24h, standard 7-day window | AgentX releases patch; customer applies within agreed SLA | Customer applies; AgentX provides CVE advisory + patch tarball |
| Scaling | Auto-scaling; no action required | Customer scales K8s nodes; AgentX provides sizing guide | Customer provisions hardware per sizing guide |
| Monitoring | AgentX observability stack; customer dashboard | Customer stack; AgentX exports OTel metrics + alerts | Customer stack; diagnostic bundle on request |
| Backups | AgentX automated; daily snapshot, 30-day retention | Customer-managed; AgentX provides export tooling | Customer-managed; RPO/RTO TBD with delivery |
| Disaster recovery | AgentX-managed; RTO/RPO TBD with delivery | Customer DR plan; AgentX runbook provided | Customer DR plan; offline restore procedure documented |
| Support access | TAM + SRE on-call; shared Slack channel | Break-glass session; audited; customer-approved | Offline diagnostic bundle; optional VPN session |
Signed update packages
Every update - cloud, hybrid, or on-prem - ships as a signed package. GPG signature and SHA-256 checksum on every release. Verify before you apply.
Documented upgrade paths
Every version bump has a documented upgrade path, rollback procedure, and compatibility matrix. We don’t drop breaking changes without a migration guide and a minimum 90-day notice window.
Defined escalation routes
P1 incidents have a direct pager to the on-call SRE. P2/P3 go through your TAM. Escalation SLAs are documented in the MSA and verified during onboarding.
SLA & support
What we commit to, what support looks like, and what you can hold us to. All in writing before you sign.
Specific SLA percentages (availability, RTO, RPO) are TBD with delivery and legal, and will be documented in your MSA before signature. Numbers on this page are illustrative of the support model, not contractual commitments until countersigned.
Exit
Exit terms are in the MSA before you sign. We don’t make leaving hard - your data is yours, your configuration is yours, and the transition period is defined.
All customer data - run history, knowledge bases, embeddings, agent configurations, and audit logs - exported in standard formats (JSON, CSV, Parquet) within 30 days of termination. Secure transfer method agreed in exit plan. AgentX-held copies purged within 30 days of confirmed receipt, with written confirmation.
Agent definitions, workflow configurations, integration mappings, and prompt templates exported as version-controlled YAML/JSON. Compatible with standard workflow tools to reduce re-build effort. API access maintained for 90 days post-termination for migration purposes.
90-day transition period (TBD with delivery) included in Enterprise exit terms. TAM remains point of contact through transition. Read-only access to platform maintained during migration window. Architecture documentation and integration specs provided to successor team.
Exit provisions are in the MSA before signature, not negotiated at termination. Data portability, purge timeline, transition period length, and post-termination API access window are all documented. No lock-in clauses, no data hostage provisions.
Read next
Deployment is one of four enterprise pillars. The others cover delivery model, security controls, and AI-specific governance.
Four-stage delivery model. Deployment is Stage 3, and the runbook differs by deployment model.
See processThe security controls for each deployment model. Encryption, access control, audit, AI-native primitives.
See securityThe governance controls that operate regardless of deployment model. Model risk, explainability, regulatory alignment.
See governanceReady for the infrastructure conversation?
A 45-minute call. We’ll walk through which deployment model fits your environment, what the network and integration requirements look like for your specific setup, and what your team would need to provide for hybrid or on-prem. We bring reference architectures. You bring your environment constraints. We match them.
Sign up for AgentX and let AI handle your routine tasks - no credit card needed.