The governed lane. In our cloud or yours.
The board told everyone to build with AI. Security can't let them ship it into prod. Salus is the lane where any team — and any agent — builds and deploys under your rules. Run it on dedicated Salus Cloud infrastructure, or inside your own cloud account. Alongside prod, not inside it.
99.99%
Control plane uptime target
< 60s
Median deploy time
SOC 2
+ ISO 27001 — audits completing, 2026
From $25
Per builder / month, plus consumption
A plan, not a place.
Enterprise is the entitlement tier — governance, isolation, support and contract terms. Where it runs is a separate decision, and not one you have to make up front.
The plan
From $25 per builder / month
Plus consumption, like every tier. You pay for builders and admins — everyone who uses what they ship is free and needs no Salus account.
See what is includedWhere it runs
Your choice, and only on this tier
Run on the managed multi-tenant Salus Cloud environment, or deploy into a dedicated, isolated target inside infrastructure you own. Free and Pro do not get that choice — it is what the Enterprise tier unlocks.
BYOC
Priced per cluster, on top
Your own public cloud account, private cloud or on-premise. BYOC is added to an Enterprise plan, never bought instead of one — so you can start on Salus Cloud and move when your compliance posture asks, without changing tier.
Run Salus where your business needs it.
The same control plane runs on Salus Cloud, on Salus hardware, or inside infrastructure you own — without forking the developer experience.
salus.cloud
Multi-tenant Cloud
For builders and teams that want to start immediately. Salus runs everything — compute, network, build, observability — on managed infrastructure.
- Instant deploys
- Managed regions
- Prepaid credits, metered per deployment
Self-serve for builders. Controlled for the business.
The controls security and platform teams need — without the friction that pushes builders back into shadow IT.
Your rules, enforced
RBAC · humans & agents
Policy gates
Release window
humans + agents · weekdays 06–20 UTC
Vulnerability scan
0 critical allowed
Egress to unlisted API
external network · not allow-listed
Blast radius
This deploy touches
3 / 12 services
within limit · cap 12 services
Last resort
Kill switch
any app · any agent · instant
Audit trail
Role-based access control
Roles scoped to your organisation, spaces and projects — Owner, Maintainer, Developer, Viewer, Guest — with SSO. An agent acts with its builder’s access, so it can never reach further than they can.
Customer-controlled environments
Per-customer trust boundaries, certificates and policy — visible to your customers, governed by you.
Append-only audit storage
Events are written once and never edited or deleted, isolated per tenant at the database level, each recording the actor and the time. An agent acting for someone is recorded as that person — agents do not yet hold their own identity in the trail. Coverage is expanding service by service.
Consumption reporting
See what every project and environment consumes, broken down by compute, databases and bandwidth, so finance can see where the spend goes.
Secure delivery workflows
Build, scan, policy and approval gates run before any change reaches production.
Isolation and an off switch
Each workload runs in its own isolated infrastructure, and any deployment can be taken offline on demand — from the console, the CLI or an agent tool call.
Governance you can report, not just claim.
Leadership is already asking how the AI mandate is going. This is the shape of the answer a governed lane gives you — the apps, the departments, the gates that held.
AI apps · quarterly update
illustrative11 apps shipped
by 4 departments — finance, HR, ops, support
0 incidents
from citizen- or AI-built apps
23 gates enforced
risky deploys blocked before they ran — the rules, working
100% in approved regions
every app in a cloud and region IT allowed
illustrative figures · roles, gates and region selection applied by the platform, not by each team
BYOC architecture · an option on Enterprise
Our control plane. Your data plane.
Run Salus-managed workloads inside infrastructure you own — your AWS, GCP, Azure or Huawei account, your private cloud, or your own on-premise Kubernetes. Salus orchestrates; your cloud holds the data, identity and network. Nothing leaves your perimeter. Quoted per cluster, on top of your Enterprise plan.
- Workloads run in your VPC, under your IAM
- Data residency stays in your region
- Customer-controlled certificates and KMS
- Public cloud, private cloud or on-premise
your-org-aws
vpc: region: eu-west-1 cidr: 10.42.0.0/16 data_plane: workloads: payments-api, ingest, dashboard gpu_pool: a100 ×8 (spot) observability: enabled salus_control_plane: endpoint: cp.salus.cloud egress_only: true identity: provider: okta rbac: org / space / project
Stop being the department of no.
Connect your cloud, your identity and your policies. Give every team — and their agents — a fast path your security team already trusts.