Choose the deployment model that matches your regulatory, sovereignty and security requirements, from managed Xybern infrastructure to isolated and customer-controlled environments. Every model enforces the same authorisation logic. What changes is where the control plane, your data and your keys reside.
Managed security infrastructure for the fastest path to enforcement. Deploy Xybern as a managed service with isolated organisation environments, encrypted data and a Xybern-hosted control plane. Best for teams that want speed and managed operations.
3.1 Xybern CloudA private Xybern environment provisioned for your organisation, with dedicated compute, isolated storage and configurable networking, retention and access controls. Best for banks, government, defence and large critical-infrastructure customers.
3.2 Dedicated EnvironmentRun Xybern inside infrastructure you control, keeping sensitive workloads, charter enforcement and security evidence within approved customer or sovereign infrastructure. You control data location, networking and encryption keys, for the highest-security and mission-critical environments.
3.3 Sovereign DeploymentThe same authorisation, delegation, MCP, approval and provenance controls run in every model. What changes is isolation, infrastructure control and data residency.
| Capability | Xybern Cloud | Dedicated | Sovereign |
|---|---|---|---|
| Managed by Xybern | Yes | Yes | Shared, customer-dependent |
| Organisation isolation | Yes | Dedicated | Customer-controlled |
| Dedicated compute | Optional | Yes | Yes |
| Customer networking | Limited, configurable | Advanced | Full control |
| Customer-controlled infrastructure | No | Partial | Yes |
| Data residency options | Yes | Yes | Customer-defined |
| Customer-controlled keys | Optional | Optional, advanced | Yes |
| Private connectivity | Optional | Yes | Yes |
| Agent-to-agent security | Yes | Yes | Yes |
| MCP security | Yes | Yes | Yes |
| External-agent federation | Yes | Yes | Yes |
| Human approval | Yes | Yes | Yes |
| Cryptographic provenance | Yes | Yes | Yes |
| Best for | Fast deployment | Regulated enterprise | Sovereign, highest security |
Where Xybern runs and how Xybern sits between an agent and execution are independent choices. Deployment covers Xybern Cloud, Dedicated and Sovereign. Integration covers API Gateway, SDK, MCP Gateway, Agent-to-Agent and Policy Enforcement Point. You can combine any deployment model with any integration pattern.
Dedicated and sovereign deployments are designed around the controls regulators expect: data location, segregation, audit rights, customer-held encryption keys, business continuity, and secure return and deletion of data on termination. Regional and sovereign options are available for data-residency and regulatory requirements, including the Kingdom of Saudi Arabia.
Tell us your regulatory, sovereignty and residency requirements, and we will map them to the right deployment model.