Deploy to your
customer’s cloud

Install, update, and monitor your software inside every customer’s own environment, from one place, with zero access to their network.

Deploys to

Your customer’s security team tells you...

“We need this running in our own cloud.”

One control plane,
every customer environment

Declare what each customer should be running. BYOC works out the difference, applies it inside their environment, and records the result.

Platform version
Set once. Applies to every customer.
All 6 on 2.13.2
Acme CorporationAWS · us-east-1Up to date · 2.13.2
GlobexAWS · eu-west-2Up to date · 2.13.2
InitechAzure · westeuropeUp to date · 2.13.2
UmbrellaGoogle Cloud · us-central1Up to date · 2.13.2
HooliAWS · ap-southeast-1Up to date · 2.13.2
VandelayOn-prem · frankfurt-dc2Up to date · 2.13.2

The connection starts
on their side

A small agent inside the customer's environment opens the connection to you. You need zero access to their network, and their firewall and credentials stay exactly as they are.

YOUControl planehosted by youYOUR CUSTOMERtheir own environmentBYOC agentcalls out to youYour productDatabaseWeb serverDashboardsCredentialsfirewallinbound: blockedoutbound only

Know exactly
what is running

Every environment reports its real state. Changes made outside BYOC are flagged, and you choose how to reconcile them.

What you asked for · Amazon5 items
Redisversion 20.6.2Present
Postgresversion 16.2.3Present
NGINXversion 18.2.5Present
Grafanaversion 8.5.1Present
Lokiversion 2.10.2Present
What is actually running5 of 5
Redisversion 20.6.2Running
Postgresversion 16.2.3Running
NGINXversion 18.2.5Running
Grafanaversion 8.5.1Running
Lokiversion 2.10.2Running
In sync. Everything matches what you asked for.

Built to pass
the security review

The questions a customer's security team asks before approving a vendor in their cloud, and the answers BYOC gives them.

How does BYOC connect to our environment?

The agent inside your environment initiates every connection to the control plane. Your network stays as it is.

Who holds our cloud credentials?

You do. The agent runs inside your environment with the permissions you grant it.

What is the agent allowed to do?

Install, update, and remove the components you have approved.

Can we audit what changed?

Yes. Every change is recorded with who requested it, when it was applied, and the result.

What if we change something ourselves?

It shows up as drift for both sides to see, and you decide what happens next.

What data leaves our environment?

The status of the software BYOC manages. Your application data stays with you.

Make customer cloud deployments routine.

Open source. Runs on a laptop in five minutes.