On-premise & air-gapped AI agents — sovereign platform | aamp
Self-hosted AI agent orchestration

Ship Your AI Projects

INPUTS FOR YOUR AI PROJECT IN / 01 Unstructured company data IN / 02 Strict privacy and data policy IN / 03 Optimized budget for LLM and AI projects IN / 04 Legacy systems ERP integration NORMALIZE / ROUTE / GOVERN THE aamp GOVERNED DELIVERY OF YOUR AI PROJECT 4-LAYER AMPLIFICATION GAIN / 0.74 LUNA OLLAMA Qwen Mistral Anymodel Sovereignty Security On-premdelivery BUDGET AUDIT ACCESS LUNA OLLAMA Qwen Mistral MODEL OUTCOMES OF YOUR AI PROJECT OUT / 01 Sales automation OUT / 02 Supply chain AI OUT / 03 RAG chatbots OUT / 04 RFI / RFP automation OUT / 05 LLM data analysis SIGNAL AMPLIFIED
illustration — audit trail

aamp is a self-hosted, air-gapped AI agent orchestration platform for LLM agents, RAG and workflows.

It runs entirely on your own infrastructure — against local model engines (vLLM, Ollama, LocalAI, TGI) or cloud APIs. You control which model sees which data, what each agent is allowed to touch, and what every call costs, with a full audit trail host-side. Nothing leaves your infrastructure unless you say it can.

  • Zero outbound telemetry
  • Local or frontier models
  • Single Go binary
  • Hardware-isolated sandboxing

Build the layer once. Swap models forever.

01 · Production agent workloads

Where do you want to deploy AI agents?

Engineering, security and operations teams run governed agents with strict host authority, microVM sandboxing and dual safety firewalls. Pick the job you have now.

01 Run RAG on documents that can’t leave the building 02 Put the GPUs we already bought to work 03 Let agents touch our ERP without risking production 04 Swap LLM models, test side-by-side open-weight vs frontier
Considering another use case? Deliver Your AI idea
02.1 · Why: Sovereignty

On your infrastructure. 100% data sovereignty, EU AI Act compliance.

Runs on your infrastructure, in your jurisdiction. No third party to trust. Full network and hardware isolation in a single binary — zero telemetry, no data leaving for the cloud, and hard coverage of GDPR, NIS2 and DORA requirements.

Your own fully isolated AI Control Plane — no data leakage, no telemetry, no regulatory exposure.

aamp screen: PII filters and agent guardrails aamp screen: logs and the agent session audit trail aamp screen: Firecracker sandbox settings
GDPR

Zero PII transfer

  • 100% Native Air-Gap — delivers zero PII transfer to external clouds.
  • Dual Safety Firewalls — filter data leaks and Prompt Injection attacks.
EU AI Act (Art. 10 & 12)

Full audit trail

  • Full Audit Trail — 14 log domains written to the local aamp.sqlite3 database.
  • Zero Training Risk — your prompts never feed external AI models.
NIS2 / DORA

Cyber-resilience

  • Firecracker MicroVM — KVM hardware isolation rules out the blast radius.
  • On-Premise Reliability — processes keep running with no SaaS dependency.

How does aamp deliver EU data sovereignty? aamp delivers data sovereignty through a Single Go Binary architecture, the aamp.sqlite3 database in 100% Air-Gap mode (zero telemetry) and the Firecracker MicroVM hardware sandbox. It shields the organisation from US CLOUD Act exposure and provides full compliance with EU AI Act (log retention across 14 domains), GDPR, NIS2 and DORA.

01

Code isolation

Firecracker MicroVM KVM Sandboxing Blast Radius Containment
02

Security

100% Native Air-Gap Zero Telemetry Dual Safety Firewalls
03

EU Compliance

EU AI Act (Art. 12) 14 Log Domains No US CLOUD Act
02.2 · Why: Cost

Predictable AI costs: no token markup and no “Step Tax”.

Pay only for completed business tasks, not for the agent's internal reasoning loops — with full freedom to plug in your own API keys or free local models.

Control your AI budget: 0% token markup and no “Step Tax”.

AGENT TURNS 5 SUCCESS RATE 100% P95 DURATION 11.6s TOKENS 10,654 AGENT OUTCOMES SUBSYSTEM PULSE
Tiered routing — three-quarters of the traffic never reaches a frontier model
01

Run model

Execution-Based Billing 1 Completed Run 0% Step Tax
02

Token markup

0% Token Markup BYOK (Bring Your Own Key) Wholesale API Rates
03

Access & B2B

Unlimited Free Viewers No Per-User Tax VAT-compliant invoicing

How does aamp lower and stabilise the cost of running AI agents? aamp uses Execution-Based Billing, with 0% markup on LLM tokens (BYOK model) and 0% "Step Tax". Unlike platforms such as Make, Zapier or Lindy.ai, which charge for every operation or reasoning loop, aamp charges only for a successfully completed task (1 completed run), with unlimited free viewer accounts.

02.3 · Why: Model freedom

Test and compare any model, bound per agent.

Full AI model freedom (Model Agnostic).
Combine any cloud and local models in one system — no vendor lock-in, wholesale rates (BYOK) and zero markup.
Any OpenAI-compatible model, bound per agent — local open weights, hosted frontier, or both.

TYPE OpenAI-compatible LOCAL OPEN WEIGHTS HOSTED FRONTIER BOTH · PER AGENT BASE URL PERIMETER HOSTED
Binding — one model per agent, swapped without touching the workflow

Combining cloud and local AI (e.g. Ollama)

  • Any Provider: Freely mix OpenAI, Anthropic or Google Bedrock with local open-weight models (Ollama, vLLM).
  • Smart Routing: Send simple queries to cheap local models and complex work to the cloud.

Zero Lock-In & BYOK model

  • Bring Your Own Key: Use your own corporate agreements and pay provider rates directly.
  • Instant Switching: Change model provider in one click, without rebuilding agent logic.

Deterministic Logic (Starlark)

  • No Hallucinated Maths: Combine text synthesis with precise computation in the sandboxed Starlark language.
  • Local PII Protection: Filter sensitive data before a request reaches external model APIs.

What is aamp’s Model Agnostic architecture and how does it work with Ollama? aamp works as a model-neutral AI Agent Control Plane. It does not impose its own models and takes no margin on tokens (BYOK). It lets you use cloud APIs (OpenAI, Anthropic) alongside local engines such as Ollama / vLLM in 100% Air-Gap mode. Ollama serves the model weights (Model Runner), while aamp provides code execution isolation (Firecracker MicroVM), dual safety firewalls and log recording for EU AI Act requirements.

01

Local engines

vLLM Ollama LocalAI TGI Llama · DeepSeek · Mistral
02

Cloud providers

AWS Bedrock Azure OpenAI Google Vertex AI Any APIOPENAI-COMPATIBLE
03

Binding and comparison

Model per agent Model per workflow Swap without rewrites A/B on your own data
03 · Who it's for

Four segments running aamp in-house.

One governed platform, four segments running it in-house — each with its own constraint, and the same control layer underneath.

Mid-Market E-commerce & High-Volume Processes

Audience

Shops and platforms handling thousands of requests a day (complaints, returns, price updates).

Problem

Runaway costs on Make/Zapier-style platforms, driven by a fee for every step of the decision loop.

What aamp gives them

Execution-Based Billing (0% Step Tax) — a flat fee per completed task instead of a financial penalty for complex agent reasoning.

Software Houses, ISVs and B2B Integrators

Audience

B2B software vendors (ERP, CRM, HRM) and automation agencies.

Problem

They need to add AI modules to their own software fast, without risking margin on “Step Tax” and tokens.

What aamp gives them

Embeddable AI Engine — plug a single Go binary in over REST API and ship your own AI features 10x faster under your own brand (White-Label / OEM).

Regulated Sector (Healthcare, Healthtech, Finance, Legal)

Audience

Organisations processing sensitive data (PII, PHI, transactional records) under GDPR, NIS2, DORA and financial supervision.

Problem

Sending data to public clouds is off the table because of leak and compliance risk.

What aamp gives them

100% Air-Gap & MicroVM — the agent runs scripts and analyses documents in a hardware-isolated environment using local models (Ollama/vLLM).

Manufacturing, Logistics and Legacy Systems (ERP / WMS / CRM)

Audience

Mature SME and mid-market companies on traditional infrastructure (e.g. Comarch XL, SAP On-Prem).

Problem

No modern APIs, and scraping supplier or government portals risks infecting the core database.

What aamp gives them

Headless Browser Sandboxing — safe browser automation and file reading inside a disposable MicroVM.

Which companies and use cases is aamp the best fit for? aamp is designed for Upper Mid-Market and Scale-up companies (50–1000 employees), B2B software vendors (ISVs and software houses) and heavily regulated sectors (healthcare, finance, legal, manufacturing). It fits where traditional no-code tools (Make, Zapier) get too expensive because of step fees, and cloud SaaS is rejected over GDPR, EU AI Act, NIS2, DORA or the lack of an Air-Gap mode.

04 · How it works

One console for every control plane.

operations · mission control
Mission Control in aamp — agent turns, success rate, P95 duration and tokens, with agent outcomes, needs-attention items, subsystem pulse and token traffic
Mission ControlRuntime outcomes, resource pressure and the work that needs attention — one host-side surface, not a dashboard bolted onto someone else's cloud.
05 · Use it when

Use aamp when…

Four operational signals that your organisation has outgrown simple SaaS tools and needs a production Control Plane.

01

When SaaS bills for AI decision loops spiral out of control

Signal

Your workflows in Make, Zapier or n8n rack up huge costs through the “Step Tax” — a fee for every step and every retry inside the agent’s reasoning loop.

What aamp does

Execution-Based Billing — you pay only for 1 completed business run, with no markup on LLM tokens (BYOK).

02

When a compliance audit (EU AI Act / GDPR / NIS2 / DORA) blocks the rollout

Signal

Legal or the DPO rejects cloud AI tools over PII leak risk, a missing audit trail or US CLOUD Act exposure.

What aamp does

100% Native Air-Gap — deployment with 14 log domains recorded in the local aamp.sqlite3 database and full network isolation.

03

When unknown code and browser scripts threaten your ERP/CRM databases

Signal

Agents have to log into supplier portals, download PDF/Excel attachments or run scripts, which creates Prompt Injection and infrastructure infection risk.

What aamp does

Firecracker MicroVM Sandboxing — every untrusted file and browser session runs in a disposable, hardware-isolated KVM microVM with zero blast radius.

04

When a clustered stack (Docker/Postgres/Redis) paralyses maintenance

Signal

DevOps loses time maintaining and upgrading multi-container environments (e.g. Dify.ai / Langflow) in on-premise deployments.

What aamp does

Single Go Binary Architecture — the whole platform with all its components starts from one binary in seconds, keeping maintenance simple.

When should organisations replace no-code tools (Make, Zapier, n8n) or Dify.ai with aamp? Moving to aamp makes sense at four key moments: 1. Cost ceiling: when step fees on SaaS platforms across long agent decision loops get too high (aamp charges per completed run and takes 0% markup on BYOK tokens). 2. Regulatory rigour: when EU AI Act, GDPR, NIS2 or DORA rule out the cloud and demand 100% Air-Gap mode with 14 audit log domains stored locally. 3. Execution safety: when an agent has to process third-party supplier files or act in a browser without risking your ERP/CRM systems (thanks to Firecracker MicroVM hardware isolation). 4. Maintenance simplicity: when the company needs a light on-premise environment without running complex Docker/Postgres clusters (deployed as a Single Go Binary).

06 · How we differ

Automation platforms connect apps. aamp governs agents.

The orchestration layer is its own category. Here is where aamp sits in it.

Swipe horizontally

Criterion / Capability aamp Cloud SaaS (e.g. Lindy, Make) OS Frameworks (e.g. Dify, Flowise) Scripts / Workflow (e.g. n8n)
Deployment modelSingle Go Binary + SQLitePure SaaS CloudDocker / CloudNode.js / Docker
Sovereignty and Air-Gap100% Native (Zero Telemetry)None (data in the cloud)Partial (needs configuration)Partial
Code execution isolationFirecracker MicroVM (Hardware)None (shared environment)None (standard container)None (container / Node)
LLM securityDual Safety Firewalls (Prompt & PII)BasicBasic / noneNone (needs external services)
Billing model0% Step Tax + BYOKCredit packs / Step TaxMessage or query countPer workflow execution

See the full comparison →

Try aamp in the sandbox.

Free sandbox · Self-host in minutes · Talk to us

07 · Partners

Partner with aamp.

Our partners offer a range of professional services — expertise and technology capabilities to help our customers both make the first step and enrich their solutions.

Implementation Partners

Consultancies and systems integrators who scope, deploy and configure aamp for a customer's environment — knowledge bases, agents, firewalls and model routing set up to match their infrastructure and policy.

MSP — Managed Service Provider Partners

Providers who run aamp on an ongoing basis for their customers — hosting, monitoring, upgrades and support — on-premise or in a managed private cloud.

Become a Partner