Deployments
Each tenant runs an isolated gateway stack (Docker) rolled out and updated through the deployment platform. Day-2 operations — upgrades, restarts, logs — live in the deployment portal.
Deployments
6
across 4 targets
On latest release
3/6
stable 1.14.2
Rollouts · 7 days
9
0 failedvia deployment agent
Agent heartbeat
100%
all agents reporting
CityGov Services
docker · gov-zone
- Version
- 1.14.1 1.14.2
- Last deploy
- 2026-06-27 16:55
AeroTech
pending
- Version
- —
- Last deploy
- —
EduNet
pending
- Version
- —
- Last deploy
- —
How deployments work
Division of responsibilities between this control plane and the deployment platform
Control plane (here)
Tenant lifecycle, policy templates, analytics, RBAC and audit — the security brain, tenant-separated by design.Deployment platform
Multi-tenant Docker rollout: versioned releases, per-tenant agents, rollout status, secrets sealing, restart/rollback and container logs.Handshake
Onboarding registers a deployment per tenant; the control plane reads rollout and heartbeat state back and flags degradation on the console.Tenant isolation & data boundary
What crosses the boundary — and what never does
Stays inside the customer environment
- · Prompts and model responses
- · Ingested documents (RAG)
- · Decrypted evidence text (sealed key, customer-held)
- · Identity provider credentials and signing keys
Visible to the e& console (metadata only)
- · Deployment health, version and agent heartbeat
- · Request counts, outcomes and risk categories
- · Latency and SLA measurements
- · Policy template assignment and rule versions