Ænix Private Cloud Platform

Open-source Cozystack (a CNCF project we create and maintain) Ænix Platform, the supported commercial distribution Aenix builds, operates and migrates it.

Aenix Private Cloud Platform is a private and hybrid sovereign cloud for regulated organizations that run cloud for themselves rather than sell it — banks, insurance carriers, public administration, telco and healthcare operators. It runs on Cozystack, the CNCF project Aenix created and maintains, and gives one Kubernetes-native control plane that coexists with existing VMware, OpenNebula and OpenShift estates instead of forcing a rip-and-replace. It adds DORA and NIS2 architecture controls built in, customer-controlled encryption keys at every data layer, audit-ready immutable logging, multi-datacenter operations with tested failover, ISO 27001 and SOC 2 alignment support, and a developer self-service layer with GitLab CI/CD and Argo CD golden paths that ships with the platform rather than as a second product. Enterprise SLA, 24/7 support and engineering training are included. No per-CPU or per-core licensing.
Aenix Private Cloud Platform console

Quick facts

  • What it is Private and hybrid sovereign cloud for regulated enterprises, built on Cozystack, with one control plane that coexists with VMware, OpenNebula and OpenShift.
  • License Apache 2.0 core (no per-CPU / per-core licensing)
  • Status Cozystack is a CNCF project (Sandbox since 2025-02-28; Incubating expected late summer 2026)
  • For Regulated enterprises — banks, insurance, public administration, telco, healthcare, regulated industrial and energy operators
  • Includes DORA / NIS2 architecture controls, ISO 27001 and SOC 2 alignment support, customer-managed keys, audit-ready logging, multi-DC operations, air-gap deployment, and the developer self-service layer
  • Engagement Multi-year platform builds; 3-6 month pilot, 9-18 months to full multi-DC production
  • Architecture Kubernetes-native, multi-DC, KubeVirt VMs and containers on one API, Cilium (eBPF) networking, LINSTOR/DRBD replicated block storage, Tenant CRD multi-tenancy, customer-controlled keys

Private and hybrid sovereign cloud for regulated organizations that run cloud for themselves. Multi-DC by design, DORA / NIS2 architecture built, one control plane that connects to VMware, OpenNebula and OpenShift rather than replacing them — on hardware you control. Developer self-service and engineering training are part of the platform, not a second purchase.

What’s included

Multi-DC private and hybrid sovereign cloud

Designed for two-or-more datacenter deployments with active-warm or active-active failover. Tested DR + backup-restore cadence for regulator review. Hybrid pattern (on-prem + cloud) supported with one control plane.

One control plane connecting to VMware / OpenNebula / OpenShift

The platform is built for coexistence, not rip-and-replace. Existing VMware Cloud Foundation, OpenStack, OpenNebula, OpenShift estates can be brought under one Cozystack-based control plane while gradual consolidation happens at the workload pace.

DORA architecture controls

  • Customer-controlled encryption keys at every data layer (Article 9)
  • Audit-ready logging via VictoriaLogs with immutable backend, sized for incident classification and reporting (Articles 17–19)
  • Multi-tenant Tenant CRD aligned with ICT asset and risk classification (Article 8)
  • Tested exit-readiness mechanics (Article 28(8))
  • Supplier transparency to the second hop, feeding the register of information (Article 28(3))

NIS2 architecture controls

  • Article 21 cybersecurity risk-management measures across 10 control areas
  • Article 23 incident handling + reporting templates aligned to 24h / 72h / 1-month timelines
  • Article 12 coordinated vulnerability disclosure aligned
  • Tenant CRD with NetworkPolicy / Cilium for segmentation

Sovereign deployment

Customer-controlled hardware in customer-controlled jurisdiction. Air-gap operation supported (no internet egress required). Customer-managed encryption keys (BYOK / HYOK) with HSM integration. Provider personnel access logged and time-limited.

Customer-managed encryption (data at rest + in transit)

Encryption keys held by the customer at every layer — primary store, replicas, backups, observability data, model weights at rest. Vendor-managed-only keys are explicitly avoided.

VictoriaLogs audit-ready logging stack

Immutable, exportable, regulator-compatible audit trail. Integration with customer SIEM. Long-tail retention meeting longest applicable regulatory requirement (often 5+ years).

Multi-tenant Tenant CRD

Tenant CRD with quota / RBAC / observability per workload. Tenant boundary enforced at network, identity, storage, observability layers — not just namespace.

Education and training included

Engineering team training as part of the engagement. Ænix’s Kubernetes Deep Dive Course covering the Cozystack stack (Talos, LINSTOR, Cilium, KubeVirt, Cluster API, Flux) included for customer engineers in Private Cloud Platform deployments.

Enterprise SLA and certification support

Tiered SLA aligned to regulator expectations, named technical account manager, defined escalation procedures. Architecture designed to support ISO 27001 and SOC 2 certification work; Ænix supplies the certification documentation and audit-readiness work.


Developer self-service (internal developer platform)

Included in the platform rather than sold as a second product, and switched off for organizations that do not want it. It turns the multi-tenant substrate into something your engineers touch directly:

  • Golden paths and service-creation wizards — engineers describe the outcome (workload, SLO, tenancy) and the platform realises it. Customizable to your organization’s patterns.
  • GitLab CI/CD integration — pre-built patterns for environments, secrets and deployment promotion, with templates for web services, workers, batch jobs and ML pipelines. GitHub and Bitbucket supported as alternatives.
  • Argo CD GitOps — multi-cluster, multi-environment app-of-apps setup, PR-driven change for application and infrastructure, drift detection and remediation.
  • Self-service APIs — environments, managed databases (PostgreSQL, MariaDB, Valkey, Kafka, ClickHouse), object storage, Kubernetes clusters, observability scopes and identity bindings, without ticket queues.
  • Engineering productivity dashboards — time-to-environment, deployment frequency, lead time, drift events.

The Tenant CRD that carries the compliance boundary is the same object that carries the team or squad model, so a self-service environment is isolated by the control the auditor already accepted. Against building this on Backstage: Backstage is a UI framework and you still supply the cloud underneath — here the foundation and the layer above it arrive together.

Combine it with the other platforms

The three Ænix platforms are the same engine with different surfaces switched on, so they compose rather than compete. Nothing below is a separate installation or a second procurement.

  • AI Platform — GPU tenancy (H100, H200, A100, L40S, Blackwell), model serving and vector databases, inheriting the same sovereignty controls: customer-managed keys extend to model weights at rest, GPU workloads sit inside the same Tenant CRD boundary the regulator already reviewed.
  • Public Cloud Platform — billing, payments and customer-facing portals, for when the same organization also sells capacity externally. A telco running a regulated internal estate and a commercial sovereign cloud product runs both on one platform under one operations team.

The practical consequence: choosing Private Cloud Platform now does not foreclose anything later. Adding GPU tenancy or a customer-facing commercial layer is a configuration decision on the platform you already run.

Where it sits against the incumbents

Vs.The trade
NutanixNutanix sells an appliance-grade experience: HCI with Prism, one vendor for hardware and software, and an operations story that genuinely works out of the box. The costs are the licence per core, the hardware compatibility list, and an exit that gets harder each renewal — and quotes swing widely, so the same estate can price anywhere in a broad band. Ænix Private Cloud Platform runs on commodity hardware with no per-core licence, and Kubernetes is the API rather than a bolted-on add-on. Five-year TCO with quote sensitivity.
Azure Stack HCI / Azure LocalThe right answer if your target state is Azure and this is a landing zone for workloads that cannot leave the building yet: the Azure control plane, Azure billing, Azure identity, one operating model. It is also the opposite of sovereignty — the control plane is Microsoft’s, the meter runs to Microsoft, and a jurisdiction question about the control plane has one answer. Private Cloud Platform puts the control plane inside your perimeter, including fully air-gapped, with customer-managed keys.
VMware / VCF under BroadcomThe migration everyone is currently modelling. See Cozystack vs VMware and the five-year TCO.
OpenShiftA real ecosystem advantage in certified operators and images, against a per-core subscription and a heavier platform. The honest version.

Who buys it

BuyerTypical engagement
Tier-1 / tier-2 European bankDORA-aligned multi-DC sovereign cloud — multi-million-euro multi-year
Insurance carrierDORA scope + GDPR + sectoral; sovereignty for regulated workloads
Large public administrationSovereign cloud aligned with national procurement mandates
Telco operatorNIS2 essential-entity compliance + customer-cloud product opportunity
Healthcare operatorSectoral data laws + AI workloads on regulated data
Regulated industrial / energyNIS2 essential-entity + AI optimization + edge

Pricing

Multi-year platform build, quoted per RFP. Discovery call to scope.

Discuss Private Cloud Platform →


Ready to scope your build? Book a call →

Engagement structure

  • Discovery call (30 min, free)
  • Platform Readiness Assessment (5-10 days, fixed price agreed up front) — DORA / NIS2 gap analysis + architecture roadmap
  • Pilot engagement (3-6 months) — defined slice (one workload class, one BU, one site)
  • Full platform build (9-18 months) — multi-DC production deployment, compliance certification support, operations team training
  • Managed operations (optional, ongoing) — Ænix runs the platform under SLA

Platform Readiness Assessment →


Customer evidence

Tier-1 / tier-2 European bank engagements are in production and NDA-protected; naming is permitted from mid-2027 as the NDAs expire. Five deployments are written up in full, anonymized by contract but with architecture and figures intact. Reference calls with existing customers can be arranged under NDA for an active opportunity.


Book a review

Tell us your regulatory context (DORA / NIS2 / sectoral), current architecture, and sovereignty requirements — we’ll set up a focused architecture review with an Ænix engineer and confirm platform fit.

Prefer a shorter first step? Book a discovery call instead.


Ænix Private Cloud Platform is built on Cozystack — a CNCF project we created and maintain (currently CNCF Sandbox; CNCF Incubating expected late summer 2026). Apache 2.0. Ænix is the open-core company.

Frequently asked questions

How is this different from running open-source Cozystack ourselves?

Cozystack provides the Kubernetes-native multi-tenant foundation. Private Cloud Platform adds built DORA and NIS2 architecture bundles, multi-DC operations runbooks, customer-managed encryption at every layer, an audit-ready logging stack, hybrid integration with VMware, OpenNebula and OpenShift, ISO 27001 and SOC 2 alignment support, enterprise SLA with 24/7 support, and engineering training. The engine is the same and stays Apache 2.0; what you buy is the regulated-operations layer and the people who have done it before.

How is it different from Ænix Public Cloud Platform?

Who consumes the capacity. Private Cloud Platform is for organizations running cloud for their own business units, so it carries compliance architecture, customer-controlled keys and audit-ready logging. Public Cloud Platform is for operators selling cloud to external customers, so it carries billing, payments and customer-facing portals instead. Same foundation and same APIs — and a telco or bank that does both runs both on one platform rather than two.

Can it coexist with our existing VMware estate?

Yes, and that is how these programmes normally run. The platform is built for coexistence: existing VMware Cloud Foundation, OpenStack, OpenNebula and OpenShift estates come under one Cozystack-based control plane while consolidation proceeds at the pace of the workloads. Forklift-based VM migration ships in the Ænix platform, so moving a cohort does not require a separate tool or a separate project; on a self-run Cozystack cluster you deploy Forklift alongside it, since upstream self-service import is still in review.

Does the developer self-service layer come separately?

No. The internal developer platform layer — golden paths, GitLab CI/CD patterns, Argo CD GitOps, self-service APIs for environments, databases and clusters — is part of this platform rather than a separate product. Organizations that want only the regulated cloud simply leave it switched off; those that want self-service for their engineers switch it on without a second procurement.

Can we add GPU and AI workloads?

Yes. AI Platform capability runs on the same substrate and inherits the same sovereignty controls: customer-controlled keys extend to model weights at rest, and GPU tenancy uses the same Tenant CRD boundary as the rest of the estate. Regulated organizations typically add it once the cloud foundation is in production, without changing the platform underneath.

What does air-gapped operation actually mean here?

No internet egress is required for the platform to run or to be updated: images and platform releases are mirrored into the perimeter, and the control plane has no dependency on a vendor-hosted service. Provider personnel access is logged and time-limited, and encryption keys stay with the customer, including for backups and observability data.

Ready to talk?

Book a 30-minute discovery call — no commitment. We confirm fit, the right platform, and the next steps.