The governed lane. In your own cloud.
The board told everyone to build with AI. Security can't let them ship it into prod. Salus is the lane where any team — and any agent — builds and deploys into your cloud, under your rules. Alongside prod, not inside it.
99.99%
Control plane uptime target
< 60s
Median deploy time
SOC 2
+ ISO 27001 — audits completing, 2026
BYOC
AWS, GCP, Azure, Huawei or private cloud
Run Salus where your business needs it.
The same control plane runs in our cloud, your cloud, or your own Kubernetes — without forking the developer experience.
salus.cloud
Multi-tenant Cloud
For builders and teams that want to start immediately. Salus runs everything — compute, network, build, observability — on managed infrastructure.
- Instant deploys
- Managed regions
- Prepaid credits, cost caps built in
Self-serve for builders. Controlled for the business.
The controls security and platform teams need — without the friction that pushes builders back into shadow IT.
Your rules, enforced
RBAC · humans & agents
Policy gates
Release window
humans + agents · weekdays 06–20 UTC
Vulnerability scan
0 critical allowed
Egress to unlisted API
external network · not allow-listed
Blast radius
This deploy touches
3 / 12 services
within limit · cap 12 services
Last resort
Kill switch
any app · any agent · instant
Audit trail
Role-based access control
Roles scoped to your organisation, spaces and projects — Owner, Maintainer, Developer, Viewer, Guest — with SSO. An agent acts with its builder’s access, so it can never reach further than they can.
Customer-controlled environments
Per-customer trust boundaries, certificates and policy — visible to your customers, governed by you.
Append-only audit storage
Events are written once and never edited or deleted, isolated per tenant at the database level, each recording the actor and the time. Coverage is expanding service by service.
Consumption reporting
See what every project and environment consumes, broken down by compute, databases and bandwidth, so finance can see where the spend goes.
Secure delivery workflows
Build, scan, policy and approval gates run before any change reaches production.
Isolation and an off switch
Each workload runs in its own isolated infrastructure, and any deployment can be taken offline on demand — from the console, the CLI or an agent tool call.
Governance you can report, not just claim.
Leadership is already asking how the AI mandate is going. This is the shape of the answer a governed lane gives you — the apps, the departments, the gates that held.
AI apps · quarterly update
illustrative11 apps shipped
by 4 departments — finance, HR, ops, support
0 incidents
from citizen- or AI-built apps
23 gates enforced
risky deploys blocked before they ran — the rules, working
100% within caps
every app inside its IT-set spend cap
illustrative figures · roles, gates and region selection applied by the platform, not by each team
BYOC architecture
Our control plane. Your data plane.
Run Salus-managed workloads inside your own AWS, GCP, Azure or Huawei account. Salus orchestrates; your cloud holds the data, identity and network. Nothing leaves your perimeter.
- Workloads run in your VPC, under your IAM
- Data residency stays in your region
- Customer-controlled certificates and KMS
- Air-gap and self-hosted available
your-org-aws
vpc: region: eu-west-1 cidr: 10.42.0.0/16 data_plane: workloads: payments-api, ingest, dashboard gpu_pool: a100 ×8 (spot) observability: enabled salus_control_plane: endpoint: cp.salus.cloud egress_only: true identity: provider: okta rbac: org / space / project
Stop being the department of no.
Connect your cloud, your identity and your policies. Give every team — and their agents — a fast path your security team already trusts.