the dominions — private vpc
Pantheon in your private VPC.
Run the full orchestration platform single-tenant inside your own AWS or GCP account. Agents, runtime, and audit log all live within your network boundary - Obsidura operates the software, your cloud account holds the data.
What a VPC deployment gives you
- Single-tenant: your deployment shares nothing with anyone else's.
- Your network boundary: connectors reach your databases and internal services over your network, not the public internet.
- Your cloud account: the deployment runs in AWS or GCP infrastructure you own and can inspect.
The same security model, inside your walls
Nothing about the platform relaxes in a private deployment. Credentials are still minted per step with least privilege and revoked on completion, executors are still sandboxed with no egress beyond the connector allowlist, and every action still lands in the append-only audit log.
When to choose VPC
Choose a private VPC when your data governance requires that operational data stay inside infrastructure you control, but you still want a managed platform rather than hardware to run. If no external calls at all is the requirement, the on-premises deployment goes further.
Put agents on your backend.
A 30-minute call. We map one workflow and show you the audit log by the end of it.