Skip to content

Deployment profiles: Cloud, Dedicated, Saudi Private, Sovereign

One codebase, three ways to run it. The profile is a configuration choice (XYBERN_DEPLOYMENT), never a separate build.

Xybern Cloud Xybern Dedicated (Saudi Private) Xybern Sovereign
Who operates it Xybern Xybern, one environment per customer The customer
Where Xybern infrastructure Customer-chosen region (Saudi Private: OCI Riyadh, Jeddah DR) Inside the customer's boundary, air-gap capable
Surface Everything Authorisation Layer only Authorisation Layer only
Tenancy Shared, workspace-isolated Single tenant, own database and keys Single tenant, own database and keys
Licence Not applicable Optional file, informational Required signed offline file, grace period, never a shutdown
LLM for semantic mandates Xybern-managed Configurable (XYBERN_LLM_*), in-Kingdom endpoints supported Must be explicit: local model, customer key, or none
Updates Continuous Xybern deploys Signed offline bundles verified by the customer
Evidence Deployment Manifest, receipts, proof packs Same Same, plus SBOM in every bundle

The Deployment Manifest

Every install answers GET /api/v1/enforce/deployment with what it is and what leaves its boundary:

{"mode": "sovereign", "region": "SA", "single_tenant": true,
 "external_telemetry": false, "external_anchoring": false, "hosted_licence": false,
 "llm": {"provider": "openai", "endpoint": "http://llm.internal:8000/v1", "model": "allam-2-7b", "external": false},
 "licence": {"state": "valid", "customer": "…", "expires_at": "…", "days_remaining": 340}}

This is the document to attach to a security questionnaire: it is generated from the running configuration, not written by hand.

Same engine, same receipts

The policy engine, Charter, escalations, runtime sessions, Provenance Vault and the offline verifier are identical across profiles. A proof pack exported from a sovereign install verifies with the same public tools/xybern-verify as one from Xybern Cloud.

Enforcing next to the agents: the relay

For network zones that must not reach even the sovereign control plane, the self-hosted relay runs deterministic mandates locally (XYBERN_OFFLINE=1) from a signed policy bundle exported by the control plane (GET /api/v1/enforce/policies/bundle), writes a hash-chained local audit log, and fails closed on semantic mandates it cannot judge. See Self-Hosted Relay.

Runbooks

Xybern operates Dedicated / Saudi Private environments from the deploy/dedicated/ runbook; customers receive the deploy/sovereign/ package, a signed release bundle and a licence file.