Your agents. Your infrastructure.
Your data.

Runs Where Your Data Lives

Deploy the full Introspection stack inside your VPC with Terraform and Helm. Encryption keys in your own account, private networking, and a zero-secrets architecture: Workload Identity, IRSA, or Managed Identity instead of passwords.

Your VPC / Private Cloud
Data Plane API
Durable Orchestration
Trace Ingestion
Agent Management
Agent Sandboxes
Ephemeral microVMs
Default-Deny Egress
Edge Credential Injection
LLM Gateway
Bring Your Own Keys
Per-Org Budget Caps
Usage Tracking
Storage
ClickHouse (BYO or Managed)
PostgreSQL (encrypted)
Redis / Valkey (TLS)
Encrypted Connection
TLS encrypted
Outbound only
No data egress
Introspection Cloud
Dashboard & Analytics
Auth & Access Control
Deployment Management

Every run, fully isolated

Agents execute in disposable, locked-down sandboxes that can't reach your network or your secrets, and recover cleanly when things fail.

Hardened sandboxes

Every run executes in its own ephemeral, hardened sandbox (gVisor or Kata) on a commit-pinned immutable image, started from a warm pool in ~1–2 seconds and destroyed when it finishes. Nothing persists between runs.

Default-deny egress

Agents reach only the hosts you allow. Every other outbound request is rejected at an Envoy gateway, no open internet from the sandbox.

Edge credential injection

Provider keys never enter the sandbox. A short-lived token is swapped for the real credential at the gateway edge, just before the request leaves your network.

Durable execution

Every task runs as a journaled, replayable workflow, crash-safe and exactly-once. Runs survive restarts and resume where they left off, with no duplicate side effects.

Your data stays yours

Everything runs in your own cloud account, encrypted with keys you control, with per-user data you can erase on demand.

Single-tenant data plane

A dedicated cluster, database, cache, and KMS key per customer, running in your own cloud account on AWS, GCP, or Azure, never co-mingled with other tenants.

Encryption you control

Data is encrypted with a dedicated KMS key in your own account, rotated every 90 days and revocable by you at any time, across databases, caches, object storage, and disks.

Per-user memory & erasure

Per-user memory is sealed with AES-256-GCM envelope encryption keyed per member. Destroy a user's key to crypto-shred just their data, clean, GDPR-style erasure.

Bring your own ClickHouse

Point Introspection at your existing ClickHouse cluster, or let us deploy one in your VPC. Your OpenTelemetry trace data stays exactly where you want it.

Wired into your org

Tie every agent, key, and action to your identity provider and your spend, with a full audit trail behind it.

SSO & scoped access

Authenticate via OIDC, with Owner / Admin / Member tiers and 40+ fine-grained permission scopes across 20+ resource types. Signed JWTs and JWKS secure every call between planes.

Application federation

Embed agents in your product via SPA, service-account, JWKS, or native apps, and federate your partners' end-users with standard token exchange (RFC 8693).

AI gateway & budgets

Route LLM traffic through your own Anthropic, OpenAI, and Gemini accounts, with per-org budgets enforced at the edge and real-time usage analytics per task and agent.

Audit logging

Immutable, exportable audit events across 100+ action types, with full attribution, including any staff impersonation, so you can prove exactly who did what.

Deploy Your Way

Choose the deployment model that matches your security posture. Migrate between options as your needs evolve, no vendor lock-in.

Managed Cloud
We handle everything
  • Zero infrastructure to provision or maintain
  • Automatic upgrades, patches, and scaling
  • Managed sandbox orchestration with warm pools
  • Built-in LLM gateway with cost tracking
  • Multi-region availability
Self-Hosted
Full ownership
Everything in Hybrid, plus:
  • Control plane in your account
  • Auth, SSO, and member management
  • Billing and usage tracking
  • Deployment provisioning and GitOps
  • Integration credential storage

The controls a security review expects

Immutable audit logging, encryption at rest and in transit, least-privilege access, and full impersonation tracking, with the architecture to back them. Your data and prompts are never used to train models.

Start building with Introspection.