Q

2.0

Deployment Options ยท Architecture page

Same engine. Different cockpit.

One platform. Three deployment shapes. Whatever your boundary, xAQUA meets you there.

A 50-person startup deploys multi-tenant in hours. A $300B agency deploys privately inside their own VPC โ€” same platform, different boundary. The platform is the same. The cockpit is what changes.

Self-service multi-tenant for SMB. Private VPC for enterprise โ€” AWS today, Azure and GCP available. GovCloud-class for federal, state, and local agencies โ€” with air-gapped option for classified workloads. Pick the boundary. Bring your stack. Deploy.

๐ŸŒ
Three Deployment Shapes
Pick your boundary ยท keep your control plane
โšก
xAQUA Essentials
Multi-tenant SaaS ยท Hosted
Live in hours
๐Ÿข
xAQUA Enterprise
Private VPC ยท Your Cloud
Live in 3 weeks
๐Ÿ›ก๏ธ
xAQUA for Government
GovCloud ยท Air-gap option
Live in 4โ€“6 weeks
Same UDP ยท Same six agents ยท Same semantic layer
3
Deployment Shapes
3 Weeks
Enterprise Live
$300B
Largest Deployment
Air-Gap
Available
Zero
Data Egress
The Three Shapes

Pick the cockpit.
Keep the engine.

Constraint, not capability. Same UDP. Same six agents. Same semantic layer. The deployment shape changes who manages what โ€” and where the trust boundary sits.

SMB & Mid-Market
xAQUA Essentials
Multi-tenant SaaS ยท Hosted by xAQUA

Sign up, connect your data, ask your first question in minutes. The full platform โ€” built for businesses that want to move fast without an engagement.

  • Full UDP: Cezu, six agents, semantic layer
  • Connectors to your warehouse and SaaS apps
  • SSO via Google / Microsoft
  • SOC 2 Type II shared-tenant environment
  • Usage-based pricing โ€” pay as you go

xAQUA runs the platform. You run the analytics. Updates ship continuously. No infrastructure on your side.

Startups
Mid-market
Single team pilots
Up to ~250 users
Time to first answer
Live in hours
See Essentials pricing โ†’
Enterprise
xAQUA Enterprise
Private VPC ยท Your AWS / Azure / GCP

Deploy privately into your cloud. Run xAQUA as your AI data team across departments. Optional acceleration services to compress months of internal adoption into weeks.

  • Private VPC deployment in your account
  • Self-hosted LLMs on your GPUs (or BYO)
  • SSO, SAML, OIDC, SCIM, advanced RBAC
  • Full audit log streaming to your SIEM
  • Dedicated success manager ยท expert services available
  • Annual entitlement license โ€” unlimited use cases

You own the infrastructure. xAQUA delivers the platform, ships updates, and handles the runbook. Your IT team controls the boundary.

Multi-department
Regulated industries
$300B pension proven
SOC 2 ยท HIPAA ยท GDPR
Time to first answer
Live in 3 weeks
Talk to Enterprise Sales โ†’
Public Sector
xAQUA for Government
GovCloud-class ยท Air-gap option

Full compliance posture for federal, state, and local agencies. NIST CSF 2.0, NIST AI RMF, FedRAMP-Ready. Built for regulated, mission-critical workloads.

  • AWS GovCloud or Azure Gov deployment
  • Air-gapped option for classified environments
  • NIST 800-53 control mapping ยท FedRAMP-Ready posture
  • FIPS-validated cryptography ยท CJIS-aware patterns
  • California SLP procurement vehicle
  • StateRAMP authorization in progress

Your agency owns the environment. xAQUA delivers the platform with documented control mappings, evidence packages, and audit support.

Federal agencies
State agencies
Defense / intel ready
FedRAMP-Ready
Time to first answer
Live in 4โ€“6 weeks
For Government โ†’
Cloud Provider Support

Bring your cloud.
We meet it.

AWS is our primary deployment target โ€” and the proven choice at $300B+ scale. Azure, GCP, and government clouds are available for enterprise and public-sector deployments.

Cloud Provider
Essentials
Enterprise
Government
Air-Gapped
AWSAmazon Web Services ยท primary
GA
GA
GovCloud
Available
Microsoft AzureCommercial & Azure Government
Available
Azure Gov
Available
Google CloudGCP commercial
Available
Roadmap

Note: Essentials is multi-tenant SaaS hosted by xAQUA on AWS. Enterprise and Government editions deploy into your AWS, Azure, or GCP account. All deployments use the same UDP and the same six AI agents โ€” the deployment shape changes the boundary and operations model, never the platform capability.

Reference Topology ยท Enterprise VPC

Inside your boundary.
Outside your blast radius.

A typical Enterprise VPC deployment. Every xAQUA component runs inside your cloud account. Data sources stay where they always were. The LLM runs on your GPUs. Audit streams to your SIEM.

YOUR VPC ยท YOUR CLOUD ACCOUNT ยท YOUR CONTROL PLANE xAQUA TENANT (DEPLOYED IN YOUR VPC) DATA SOURCES โ„๏ธ Snowflake ๐Ÿ”ฅ Databricks ๐Ÿ˜ Postgres ๐Ÿชฃ S3 โ˜๏ธ Salesforce ๐Ÿ› ๏ธ ServiceNow Read-only ยท query in place ๐Ÿพ Cezu Router 23-route classifier โš›๏ธ Six AI Data Agents Steward ยท Gov ยท Analyst ยท Eng ยท Sci ยท BI ๐Ÿง  Semantic Layer Definitions ยท lineage ยท metrics ๐ŸŒ LLM Gateway Sanitize ยท envelope ยท audit ๐Ÿค– Self-Hosted LLM Llama 3.3 70B GPT-OSS 120B or your own model Runs on your GPUs ๐Ÿ“‹ Audit & Telemetry Every prompt ยท Every action Immutable log Streamed to your SIEM YOUR SECURITY STACK ๐Ÿ”‘ Okta / Azure AD ๐Ÿ›ก๏ธ SIEM (Splunk) ๐Ÿ“Š Datadog ๐Ÿ” Vault / KMS ๐Ÿ“‹ Drata / GRC ๐ŸŒ Egress firewall SSO ยท audit ยท controls EVERYTHING INSIDE THE DASHED LINE IS YOURS โ€” xAQUA NEVER LEAVES YOUR BOUNDARY
Your VPC / cloud account
xAQUA tenant (deployed inside your VPC)
Customer trust boundary
Live in Three Weeks

Enterprise deployment.
Week-by-week.

A typical Enterprise VPC deployment takes three weeks from kickoff to first production answer. The $300B+ pension fund deployment hit 8ร— ROI by week three. This is what those weeks look like.

W0
Week 0 ยท Kickoff
Discovery & environment prep
Architecture review with your team. Cloud account, VPC, IAM roles, and KMS keys set up. SSO and SCIM connections drafted. Your first three target use cases scoped.
Architecture doc
Cloud landing zone
Use case shortlist
W1
Week 1 ยท Platform install
UDP deployed in your VPC
xAQUA UDP deployed via Terraform / Helm into your account. SSO live. Audit log streaming to your SIEM. First two data source connections established. Cezu and the six agents online behind your firewall.
UDP live
SSO active
Audit streaming
2 sources connected
W2
Week 2 ยท Semantic layer + first agents
Your business language, captured
AI Data Steward catalogs your sources. Semantic layer populated โ€” metrics, dimensions, business glossary. Governance agent enforces quality and PII handling. First three real questions answered correctly.
Catalog live
Semantic layer populated
PII rules active
First answers
W3
Week 3 ยท Production go-live
Real users ยท real workflows ยท real value
Pilot user group onboarded โ€” typically 10โ€“25 analysts. First production use cases live: Chat with Data, automated reports, pipeline migrations. Compounding starts now โ€” every new question makes the next one cheaper.
Production users
Use cases live
Backlog processing
8ร— ROI achievable

Government deployments add 1โ€“3 weeks for compliance evidence packaging, ATO support, and any agency-specific runbook requirements.

What's Required

No surprises.
No hidden footprint.

A reference Enterprise deployment is documented down to the IAM roles. Here's what your platform team needs to provision before kickoff.

โ˜๏ธ
Cloud Account & Network
Account Dedicated AWS / Azure / GCP account or subscription for xAQUA tenant VPC Private VPC with at least 3 AZs, private subnets, NAT egress (or VPC endpoints) Egress No internet egress required for runtime โ€” only update/registry pull during deployment DNS Private hosted zone for internal service discovery
โš™๏ธ
Compute & Orchestration
Runtime Kubernetes (EKS / AKS / GKE) โ€” managed cluster, ~16 vCPU baseline GPU For self-hosted LLM: 2ร— A100 / H100 (or equivalent inference instances) Postgres Managed Postgres 14+ with pgvector for semantic embeddings Storage Object storage (S3 / Blob / GCS) for model artifacts and exports
๐Ÿ”
Identity & Access
SSO SAML 2.0 or OIDC โ€” Okta, Azure AD, Google, Ping, OneLogin SCIM Optional SCIM 2.0 for automated user provisioning RBAC Role mapping from your IdP groups โ†’ xAQUA roles & data scopes Secrets Integration with AWS Secrets Manager, Vault, or Azure Key Vault
๐Ÿ“Š
Observability & Audit
Logs Audit log stream to your SIEM โ€” Splunk, Datadog, Sentinel, Sumo Metrics Prometheus-compatible export ยท Datadog / New Relic integrations Tracing OpenTelemetry traces for request flow across Cezu, agents, modules Backup Postgres snapshots and config backups to your storage account
๐Ÿ”Œ
Data Connectivity
Warehouses Snowflake, Databricks, MotherDuck, BigQuery, Redshift, Synapse Databases Postgres, MySQL, SQL Server, Oracle, MongoDB, DynamoDB SaaS Salesforce, ServiceNow, Workday, NetSuite, HubSpot, Box, Drive Files S3, Azure Blob, GCS, SFTP, network shares
๐Ÿ›ก๏ธ
Compliance Add-ons
FIPS FIPS 140-2 / 140-3 validated cryptographic modules for Gov deployments Air-gap Disconnected AWS / Azure Gov isolated regions ยท offline installation bundle CMK Customer-managed encryption keys (BYOK) via KMS / Key Vault Residency Region pinning ยท EU-only / US-only / Gov-only data plane

Pick your boundary.
We'll meet you there.

Hosted SaaS for SMB. Private VPC for Enterprise. GovCloud-class with air-gap option for Government. Same UDP. Different cockpit.