Salus
For IT, security & platform leaders

The governed lane. In our cloud or yours.

The board told everyone to build with AI. Security can't let them ship it into prod. Salus is the lane where any team — and any agent — builds and deploys under your rules. Run it on dedicated Salus Cloud infrastructure, or inside your own cloud account. Alongside prod, not inside it.

99.99%

Control plane uptime target

< 60s

Median deploy time

SOC 2

+ ISO 27001 — audits completing, 2026

From $25

Per builder / month, plus consumption

What Enterprise is

A plan, not a place.

Enterprise is the entitlement tier — governance, isolation, support and contract terms. Where it runs is a separate decision, and not one you have to make up front.

The plan

From $25 per builder / month

Plus consumption, like every tier. You pay for builders and admins — everyone who uses what they ship is free and needs no Salus account.

See what is included

Where it runs

Your choice, and only on this tier

Run on the managed multi-tenant Salus Cloud environment, or deploy into a dedicated, isolated target inside infrastructure you own. Free and Pro do not get that choice — it is what the Enterprise tier unlocks.

BYOC

Priced per cluster, on top

Your own public cloud account, private cloud or on-premise. BYOC is added to an Enterprise plan, never bought instead of one — so you can start on Salus Cloud and move when your compliance posture asks, without changing tier.

Deployment models

Run Salus where your business needs it.

The same control plane runs on Salus Cloud, on Salus hardware, or inside infrastructure you own — without forking the developer experience.

salus.cloud

Multi-tenant Cloud

For builders and teams that want to start immediately. Salus runs everything — compute, network, build, observability — on managed infrastructure.

  • Instant deploys
  • Managed regions
  • Prepaid credits, metered per deployment
Governance

Self-serve for builders. Controlled for the business.

The controls security and platform teams need — without the friction that pushes builders back into shadow IT.

Your rules, enforced

org-policy · production lane

RBAC · humans & agents

[email protected]builder
deploylogsenv vars
claude-codeagent-builder
deployrollbacklogs

Policy gates

Release window

humans + agents · weekdays 06–20 UTC

passedblockedpendingwaiting

Vulnerability scan

0 critical allowed

passedblockedpendingwaiting

Egress to unlisted API

external network · not allow-listed

passedblockedpendingwaiting

Blast radius

This deploy touches

3 / 12 services

within limit · cap 12 services

Last resort

Kill switch

any app · any agent · instant

armed

Audit trail

agent · mcpclaude-codedeploy14:02 UTC
human[email protected]env var set13:47 UTC
agent · mcpops-copilotrollback11:20 UTC

Role-based access control

Roles scoped to your organisation, spaces and projects — Owner, Maintainer, Developer, Viewer, Guest — with SSO. An agent acts with its builder’s access, so it can never reach further than they can.

Customer-controlled environments

Per-customer trust boundaries, certificates and policy — visible to your customers, governed by you.

Append-only audit storage

Events are written once and never edited or deleted, isolated per tenant at the database level, each recording the actor and the time. An agent acting for someone is recorded as that person — agents do not yet hold their own identity in the trail. Coverage is expanding service by service.

Consumption reporting

See what every project and environment consumes, broken down by compute, databases and bandwidth, so finance can see where the spend goes.

Secure delivery workflows

Build, scan, policy and approval gates run before any change reaches production.

Isolation and an off switch

Each workload runs in its own isolated infrastructure, and any deployment can be taken offline on demand — from the console, the CLI or an agent tool call.

The story you'll tell

Governance you can report, not just claim.

Leadership is already asking how the AI mandate is going. This is the shape of the answer a governed lane gives you — the apps, the departments, the gates that held.

AI apps · quarterly update

illustrative

11 apps shipped

by 4 departments — finance, HR, ops, support

0 incidents

from citizen- or AI-built apps

23 gates enforced

risky deploys blocked before they ran — the rules, working

100% in approved regions

every app in a cloud and region IT allowed

illustrative figures · roles, gates and region selection applied by the platform, not by each team

BYOC architecture · an option on Enterprise

Our control plane. Your data plane.

Run Salus-managed workloads inside infrastructure you own — your AWS, GCP, Azure or Huawei account, your private cloud, or your own on-premise Kubernetes. Salus orchestrates; your cloud holds the data, identity and network. Nothing leaves your perimeter. Quoted per cluster, on top of your Enterprise plan.

  • Workloads run in your VPC, under your IAM
  • Data residency stays in your region
  • Customer-controlled certificates and KMS
  • Public cloud, private cloud or on-premise

your-org-aws

vpc:
  region: eu-west-1
  cidr: 10.42.0.0/16
data_plane:
  workloads: payments-api, ingest, dashboard
  gpu_pool: a100 ×8 (spot)
  observability: enabled
salus_control_plane:
  endpoint: cp.salus.cloud
  egress_only: true
identity:
  provider: okta
  rbac: org / space / project

Stop being the department of no.

Connect your cloud, your identity and your policies. Give every team — and their agents — a fast path your security team already trusts.