Platform Engineer DevOps Engineer CISO CTO

Run the platform
on your infrastructure.

Whether you're operating Kubernetes in your customer's data centre, running a sovereign private cloud, or managing an air-gapped environment — mogenius deploys in-cluster, requires no data egress, and gives you governed AI operations on infrastructure that never leaves your control.

Customer Cloud AWS · Azure · GCP in-cluster healthy On-Premises Private Data Centre in-cluster healthy Air-Gapped Isolated / Regulated in-cluster healthy

Enterprise K8s doesn't
live in one cloud.

Regulated industries, ISVs delivering into customer environments, and sovereign cloud operators face a constraint most K8s tools ignore: the platform must run where the data lives — not where it's convenient for the vendor.

🏦

Regulated industries

Banks, insurers, and healthcare organisations operating under DSGVO, BSI IT-Grundschutz, or BaFin requirements cannot route operational data through external SaaS platforms. Governance must be local.

DSGVO · BSI · BaFin
🏢

ISVs & managed service providers

Software vendors and MSPs deploying Kubernetes into customer environments need a platform that runs inside the customer's perimeter — not phoning home to a vendor-controlled control plane.

Customer-cloud delivery
🔒

Air-gapped & sovereign cloud

Defence, critical infrastructure, and public sector organisations running K8s in fully isolated networks need AI governance that functions without any external network dependency — including the LLM endpoint.

Air-gapped · sovereign

Any infrastructure.
Full governance.

01
Supported

On-Premises Deployment

The mogenius operator deploys directly to your on-prem Kubernetes cluster — bare metal, VMware, OpenShift, or any CNCF-conformant distribution. All platform state is stored as CRDs in your cluster. No control-plane traffic leaves your network boundary.

  • Full platform feature parity with cloud deployments
  • Control plane runs in-cluster — no external dependency for enforcement
  • Audit log stored locally in open JSON format
  • Compatible with internal PKI, LDAP/AD identity providers
  • LLM endpoint configurable — use your own self-hosted model
On-Prem Deployment · Data Flow
mogenius operatorin-cluster ✓
Policy enginein-cluster ✓
Audit loglocal storage ✓
LLM endpointself-hosted ✓
External egressnone required ✓
Network boundary100% your perimeter
Air-Gapped · Component Status
Operator image registryprivate registry ✓
Helm chart deliveryair-gap bundle ✓
LLM inferenceOllama / local model ✓
Upgrade mechanismOLM offline ✓
Compliance exportlocal file / internal SIEM
Internet dependencyzero ✓
02
Supported

Air-Gapped Environments

For environments with no internet connectivity — defence, critical infrastructure, classified networks — mogenius ships as a fully self-contained air-gap bundle. Container images via private registry, LLM inference via Ollama or your own model, upgrades via OLM offline delivery.

  • Air-gap installation bundle with all container images
  • Private image registry support (Harbor, JFrog, Nexus)
  • Ollama integration for fully local LLM inference
  • Offline OLM-based operator upgrades
  • Compliance export to local file or internal SIEM — no external SaaS required
03
Supported

Customer Cloud Delivery

ISVs and MSPs use mogenius as the governance and operations layer they deploy into customer environments. Each customer gets their own operator instance running in their cluster — fully isolated, independently managed, no cross-customer data flow.

  • Per-customer operator instance — full isolation by design
  • Configurable branding and white-label packaging
  • Multi-tenant control plane optional for MSPs managing fleets
  • Compliance evidence exportable to customer's own ISMS platform
  • Works inside customer VPCs, private clouds, and on-prem DCs
ISV / MSP Delivery Model
Customer A · their cluster
mogenius operatorisolated instance
Audit logcustomer storage
Customer B · their cluster
mogenius operatorisolated instance
Audit logcustomer storage
Cross-customer data flownone ✓

DACH-ready.
Compliance-first.

mogenius is built and operated in Germany. For enterprises operating under BSI IT-Grundschutz, DSGVO, or sector-specific regulatory requirements, the data sovereignty model is explicit and auditable.

📍

Data stays where you define it

Operational data — action logs, audit trails, cluster state — never leaves your infrastructure boundary unless you explicitly configure export targets. The operator enforces this at the network policy level, not just by configuration.

  • No required egress of operational or workload data
  • LLM API calls routable to in-cluster or private endpoint
  • Compliance export targets fully configurable (internal SIEM, S3-compatible, or none)
📋

Regulatory alignment

For enterprises undergoing ISO 27001 certification or BSI IT-Grundschutz assessment, the mogenius on-prem deployment model maps directly to control requirements around cloud service governance, data residency, and third-party access.

  • ISO 27001 A.5.23 — Cloud services governance control mappable to on-prem config
  • BSI IT-Grundschutz OPS.1.1 — infrastructure operations evidence generated continuously
  • DSGVO Art. 28 — processor agreement scoped to what mogenius actually receives

Policies live in your cluster,
not in our platform.

The mogenius operator is open-source under Apache 2.0. Policies are stored as CRDs in your cluster. If mogenius ceases to exist tomorrow, enforcement continues — because governance cannot have a single point of vendor failure.

Apache
2.0 open-source operator — fork it, own it, run it
CRD
Policies stored in your cluster, not in a vendor SaaS
Open
JSON audit log — import to any log pipeline or SIEM
Zero
Required egress — enforcement works fully disconnected

Frequently Asked Questions

What does customer cloud and on-prem deployment mean as a use case?

SaaS and software vendors unlock new markets by serving customers with strict compliance requirements. mogenius enables deploying the vendor's solution directly into the customer's infrastructure, in their cloud account, data center, or air-gapped environment, while preserving full data sovereignty. Vendors win customers who would otherwise not accept a classic SaaS model for regulatory reasons.

Why are customers increasingly asking for on-prem or BYOC deployments?

Vendors anticipate growing market demand early and position themselves strategically. Drivers include regulations such as GDPR, KRITIS, BaFin, and DORA, data sovereignty, compliance audits, network isolation, and cost control over the own infrastructure, particularly strong in financial services, healthcare, public administration, and the DACH region. Software vendors with a BYOC option tap into these customer segments while pure SaaS vendors stay outside.

How does mogenius enable deployments into customer environments?

Vendors drastically reduce the operational effort per customer deployment and scale their distribution model. The mogenius operator runs on any Kubernetes cluster, including air-gapped, and handles deployment, updates, monitoring, and troubleshooting in a standardized way. Software vendors package their application once as a Helm chart and roll it out uniformly to all customers via the platform, instead of maintaining each installation individually.

What advantages does mogenius offer over a self-built deployment tool?

Product teams focus on their core product instead of deployment infrastructure. mogenius handles cluster management, updates, observability, secrets handling, and RBAC with consistent standards across all customer deployments, including optional governance for AI agents. Organizations save the development and maintenance of a custom deployment framework and benefit from continuous product improvements of the platform.

Is the platform usable in air-gapped environments?

Vendors can also serve customers in high-security environments without compromising on functionality. mogenius supports air-gapped deployments without internet access, including full offline rollout of operator, container images, and policies, which are stored as CRDs within the cluster. Even customers with the strictest security policies, such as in public administration or defense, can be served.

How can AI workloads be run securely in customer environments?

Vendors can extend their product with AI features without creating compliance risks for customers. mogenius includes a governance layer that restricts AI agents to role-based access, attributes and audits every action, and supports self-hosted LLMs such as Ollama. Software vendors can roll out AI features even to customers who cannot use public LLM services for data sovereignty reasons.

Your infrastructure.
Full governance.

Tell us about your environment — on-prem, air-gapped, customer cloud, or sovereign. We'll show you exactly what deployment looks like.

Certifications & Memberships

mogenius is a CNCF Silver Member, a Certified Kubernetes product, and ISO 27001 certified via TÜV Saarland.