Private and hybrid sovereign cloud for regulated organizations that run cloud for themselves. Multi-DC by design, DORA / NIS2 architecture built, one control plane that connects to VMware, OpenNebula and OpenShift rather than replacing them — on hardware you control. Developer self-service and engineering training are part of the platform, not a second purchase.
What’s included
Multi-DC private and hybrid sovereign cloud
Designed for two-or-more datacenter deployments with active-warm or active-active failover. Tested DR + backup-restore cadence for regulator review. Hybrid pattern (on-prem + cloud) supported with one control plane.
One control plane connecting to VMware / OpenNebula / OpenShift
The platform is built for coexistence, not rip-and-replace. Existing VMware Cloud Foundation, OpenStack, OpenNebula, OpenShift estates can be brought under one Cozystack-based control plane while gradual consolidation happens at the workload pace.
DORA architecture controls
- Customer-controlled encryption keys at every data layer (Article 9)
- Audit-ready logging via VictoriaLogs with immutable backend, sized for incident classification and reporting (Articles 17–19)
- Multi-tenant Tenant CRD aligned with ICT asset and risk classification (Article 8)
- Tested exit-readiness mechanics (Article 28(8))
- Supplier transparency to the second hop, feeding the register of information (Article 28(3))
NIS2 architecture controls
- Article 21 cybersecurity risk-management measures across 10 control areas
- Article 23 incident handling + reporting templates aligned to 24h / 72h / 1-month timelines
- Article 12 coordinated vulnerability disclosure aligned
- Tenant CRD with NetworkPolicy / Cilium for segmentation
Sovereign deployment
Customer-controlled hardware in customer-controlled jurisdiction. Air-gap operation supported (no internet egress required). Customer-managed encryption keys (BYOK / HYOK) with HSM integration. Provider personnel access logged and time-limited.
Customer-managed encryption (data at rest + in transit)
Encryption keys held by the customer at every layer — primary store, replicas, backups, observability data, model weights at rest. Vendor-managed-only keys are explicitly avoided.
VictoriaLogs audit-ready logging stack
Immutable, exportable, regulator-compatible audit trail. Integration with customer SIEM. Long-tail retention meeting longest applicable regulatory requirement (often 5+ years).
Multi-tenant Tenant CRD
Tenant CRD with quota / RBAC / observability per workload. Tenant boundary enforced at network, identity, storage, observability layers — not just namespace.
Education and training included
Engineering team training as part of the engagement. Ænix’s Kubernetes Deep Dive Course covering the Cozystack stack (Talos, LINSTOR, Cilium, KubeVirt, Cluster API, Flux) included for customer engineers in Private Cloud Platform deployments.
Enterprise SLA and certification support
Tiered SLA aligned to regulator expectations, named technical account manager, defined escalation procedures. Architecture designed to support ISO 27001 and SOC 2 certification work; Ænix supplies the certification documentation and audit-readiness work.
Developer self-service (internal developer platform)
Included in the platform rather than sold as a second product, and switched off for organizations that do not want it. It turns the multi-tenant substrate into something your engineers touch directly:
- Golden paths and service-creation wizards — engineers describe the outcome (workload, SLO, tenancy) and the platform realises it. Customizable to your organization’s patterns.
- GitLab CI/CD integration — pre-built patterns for environments, secrets and deployment promotion, with templates for web services, workers, batch jobs and ML pipelines. GitHub and Bitbucket supported as alternatives.
- Argo CD GitOps — multi-cluster, multi-environment app-of-apps setup, PR-driven change for application and infrastructure, drift detection and remediation.
- Self-service APIs — environments, managed databases (PostgreSQL, MariaDB, Valkey, Kafka, ClickHouse), object storage, Kubernetes clusters, observability scopes and identity bindings, without ticket queues.
- Engineering productivity dashboards — time-to-environment, deployment frequency, lead time, drift events.
The Tenant CRD that carries the compliance boundary is the same object that carries the team or squad model, so a self-service environment is isolated by the control the auditor already accepted. Against building this on Backstage: Backstage is a UI framework and you still supply the cloud underneath — here the foundation and the layer above it arrive together.
Combine it with the other platforms
The three Ænix platforms are the same engine with different surfaces switched on, so they compose rather than compete. Nothing below is a separate installation or a second procurement.
- AI Platform — GPU tenancy (H100, H200, A100, L40S, Blackwell), model serving and vector databases, inheriting the same sovereignty controls: customer-managed keys extend to model weights at rest, GPU workloads sit inside the same Tenant CRD boundary the regulator already reviewed.
- Public Cloud Platform — billing, payments and customer-facing portals, for when the same organization also sells capacity externally. A telco running a regulated internal estate and a commercial sovereign cloud product runs both on one platform under one operations team.
The practical consequence: choosing Private Cloud Platform now does not foreclose anything later. Adding GPU tenancy or a customer-facing commercial layer is a configuration decision on the platform you already run.
Where it sits against the incumbents
| Vs. | The trade |
|---|---|
| Nutanix | Nutanix sells an appliance-grade experience: HCI with Prism, one vendor for hardware and software, and an operations story that genuinely works out of the box. The costs are the licence per core, the hardware compatibility list, and an exit that gets harder each renewal — and quotes swing widely, so the same estate can price anywhere in a broad band. Ænix Private Cloud Platform runs on commodity hardware with no per-core licence, and Kubernetes is the API rather than a bolted-on add-on. Five-year TCO with quote sensitivity. |
| Azure Stack HCI / Azure Local | The right answer if your target state is Azure and this is a landing zone for workloads that cannot leave the building yet: the Azure control plane, Azure billing, Azure identity, one operating model. It is also the opposite of sovereignty — the control plane is Microsoft’s, the meter runs to Microsoft, and a jurisdiction question about the control plane has one answer. Private Cloud Platform puts the control plane inside your perimeter, including fully air-gapped, with customer-managed keys. |
| VMware / VCF under Broadcom | The migration everyone is currently modelling. See Cozystack vs VMware and the five-year TCO. |
| OpenShift | A real ecosystem advantage in certified operators and images, against a per-core subscription and a heavier platform. The honest version. |
Who buys it
| Buyer | Typical engagement |
|---|---|
| Tier-1 / tier-2 European bank | DORA-aligned multi-DC sovereign cloud — multi-million-euro multi-year |
| Insurance carrier | DORA scope + GDPR + sectoral; sovereignty for regulated workloads |
| Large public administration | Sovereign cloud aligned with national procurement mandates |
| Telco operator | NIS2 essential-entity compliance + customer-cloud product opportunity |
| Healthcare operator | Sectoral data laws + AI workloads on regulated data |
| Regulated industrial / energy | NIS2 essential-entity + AI optimization + edge |
Pricing
Multi-year platform build, quoted per RFP. Discovery call to scope.
Discuss Private Cloud Platform →
Engagement structure
- Discovery call (30 min, free)
- Platform Readiness Assessment (5-10 days, fixed price agreed up front) — DORA / NIS2 gap analysis + architecture roadmap
- Pilot engagement (3-6 months) — defined slice (one workload class, one BU, one site)
- Full platform build (9-18 months) — multi-DC production deployment, compliance certification support, operations team training
- Managed operations (optional, ongoing) — Ænix runs the platform under SLA
Platform Readiness Assessment →
Customer evidence
Tier-1 / tier-2 European bank engagements are in production and NDA-protected; naming is permitted from mid-2027 as the NDAs expire. Five deployments are written up in full, anonymized by contract but with architecture and figures intact. Reference calls with existing customers can be arranged under NDA for an active opportunity.
Book a review
Tell us your regulatory context (DORA / NIS2 / sectoral), current architecture, and sovereignty requirements — we’ll set up a focused architecture review with an Ænix engineer and confirm platform fit.
Prefer a shorter first step? Book a discovery call instead.
Ænix Private Cloud Platform is built on Cozystack — a CNCF project we created and maintain (currently CNCF Sandbox; CNCF Incubating expected late summer 2026). Apache 2.0. Ænix is the open-core company.
