aamp — Air-Gapped, Self-Hosted LLM Agent Control Plane
Self-hosted AI agent orchestration

Ship your AI projects {{ flipWord }} said no to.

aamp is a self-hosted, air-gapped AI agent orchestration platform for LLM agents, RAG and workflows. It runs entirely on your own infrastructure — against local model engines (vLLM, Ollama, LocalAI, TGI) or cloud APIs. You control which model sees which data, what each agent is allowed to touch, and what every call costs, with a full audit trail host-side. Nothing leaves unless you say it can.

  • Zero outbound telemetry
  • Local or frontier models
  • Single Go binary
  • Hardware-isolated sandboxing

Build the layer once. Swap models forever.

01 · Production agent workloads

Where do you want to deploy AI agents?

Engineering, security and operations teams run governed agents with strict host authority, microVM sandboxing and dual safety firewalls. Pick the job you have now.

01 Run RAG on documents that can’t leave the building 02 Put the GPUs we already bought to work 03 Let agents touch our ERP without risking production 04 Swap LLM models, test side-by-side open-weight vs frontier
Considering another use case? Deliver Your AI idea
02.1 · Why: Sovereignty

On your infrastructure. 100% EU regulatory compliance.

Runs on your infrastructure, in your jurisdiction. No third party to trust.

AGENTS MODELS DOCUMENTS LOGS SECRETS Nothing leaves
Perimeter — agents, models, documents and logs, all host-side
01

Perimeter and execution

Single binaryGO Local databaseSQLITE IsolationFIRECRACKER Air-gap mode HostLINUX / KVM
02

Access and secrets

Secret vaultAES-256-GCM PasswordsARGON2ID RBAC35 PERMISSIONS Resource families9 Host-side keys
03

Audit and compliance

Logs14 DOMAINS Outbound telemetryZERO GDPR EU AI Act NIS2 DORA
02.2 · Why: Cost

Pick the most cost-efficient model: instant visibility into token spend.

Routing, loop caps and per-agent budgets, built into the architecture. Not bolted on after the first invoice.

AGENT TURNS 5 SUCCESS RATE 100% P95 DURATION 11.6s TOKENS 10,654 AGENT OUTCOMES SUBSYSTEM PULSE
Tiered routing — three-quarters of the traffic never reaches a frontier model
01

Routing and caps

Tiered routing Loop step cap Per-agent budget Prompt caching Hard stop on overrun
02

Billing

Per completed run No token markup No per-step surcharge No credit ceilings
03

Cost visibility

Tokens per agent Tokens per workflow Prompt, cache and output split Accounting logs14 DOMAINS
02.3 · Why: Model freedom

Any OpenAI-compatible model, bound per agent.

Any OpenAI-compatible model, bound per agent — local open weights, hosted frontier, or both.

TYPE OpenAI-compatible LOCAL OPEN WEIGHTS HOSTED FRONTIER BOTH · PER AGENT BASE URL PERIMETER HOSTED
Binding — one model per agent, swapped without touching the workflow
01

Local engines

vLLM Ollama LocalAI TGI Llama · DeepSeek · Mistral
02

Cloud providers

AWS Bedrock Azure OpenAI Google Vertex AI Any APIOPENAI-COMPATIBLE
03

Binding and comparison

Model per agent Model per workflow Swap without rewrites A/B on your own data
03 · Who it's for

What tech and non-tech users build on aamp.

Our solution is for both technical skill-level users and non-technical business users. One governed platform, two ways in — developer-led logic for the teams who want it, visual modules and connectors for the teams who don't.

Selection 1

Technical skills’ users

Developers, Data and DevOps engineers, and Tech Ops teams.

What they love
  • Hyper-light VM and a single-binary footprint
  • Ultra-customisable platform with advanced capabilities
  • Custom developer-led logic, not boxed-in templates
  • Strict local data residency requirements kept intact
Selection 2

Non-technical skills’ users

Project managers, business operations, general business teams, marketeers and sales.

What they love
  • Low-code to code-free, with basic visual modules
  • Easy connectors instead of custom code execution
  • Complies with data sovereignty demands — self-hosted, on-prem, air-gapped
  • No dependency on an engineering queue to ship
Interested in a Guided Tour?
04 · How it works

One console for every control plane.

operations · mission control
Mission Control in aamp — agent turns, success rate, P95 duration and tokens, with agent outcomes, needs-attention items, subsystem pulse and token traffic
Mission ControlRuntime outcomes, resource pressure and the work that needs attention — one host-side surface, not a dashboard bolted onto someone else's cloud.
05 · Use it when

Use aamp when…

01

…you're giving AI agents a safe sandbox to build and run in.

02

…you're connecting AI to legacy systems with no API — ERP, CRM, finance.

03

…you're in a regulated sector and every AI action has to be explainable.

04

…you're done watching agents burn $4 in tokens to save 15 minutes.

06 · How we differ

Automation platforms connect apps. aamp governs agents.

The orchestration layer is its own category. Here is where aamp sits in it.

Dimension aamp n8n make.com Direct APIs
Runs on your infrastructureYesSelf-host optionNoNo
Agent sandboxing and audit trailYesNoNoNo
Tiered routing and loop capsYesNoNoNo
Model-agnostic, local or hostedYesConnector-levelConnector-levelNo
Cost stays flat as you automate moreYesNoNoNo

See the full comparison →

Try aamp in the sandbox.

Free sandbox · Self-host in minutes · Talk to us

07 · Partners

Partner with aamp.

Our partners offer a range of professional services — expertise and technology capabilities to help our customers both make the first step and enrich their solutions.

Implementation Partners

Consultancies and systems integrators who scope, deploy and configure aamp for a customer's environment — knowledge bases, agents, firewalls and model routing set up to match their infrastructure and policy.

MSP — Managed Service Provider Partners

Providers who run aamp on an ongoing basis for their customers — hosting, monitoring, upgrades and support — on-premise or in a managed private cloud.

Become a Partner