Customer-controlled execution for every environment
Zof generates governed test intelligence, packages signed capsules, and executes through customer-controlled runners, without requiring protected applications to call external AI services.
No inbound access required
No external model calls from protected networks
Signed immutable test capsules
Human approval for governed remediation
Three planes. One governed execution model.
Intelligence and control stay where policy allows; execution stays inside your boundary. Sensitive data remains in the execution plane unless you approve egress.
Intelligence Plane
Governed test intelligence
Planning, generation, and prioritization run where policy permits, Zof Cloud, private cloud, or on-prem.
- -System Graph and workflow understanding
- -Risk prioritization and test generation
- -Signed capsule assembly
- -Remediation planning where permitted
- -No direct execution against protected apps from external SaaS
Control Plane
Approvals and policy
Customer-governed layer for signing, scheduling, audit trails, and evidence routing.
- -Human approval workflows
- -Cryptographic signing and policy enforcement
- -Capsule versioning and promotion
- -Role-based access and SSO integration
- -Audit-ready records for every action
Execution Plane
Customer-controlled execution
Tests run inside your infrastructure. Sensitive data stays inside unless you approve egress.
- -Local edge runner execution
- -Browser, API, and desktop validation
- -Local evidence capture and redaction
- -Optional sanitized or metadata-only egress
- -No external model calls from protected networks at runtime
Secure enclave architecture
Intelligence and control operate outside the protected segment; execution and evidence stay inside via signed capsules and customer-controlled runners.
Approved planning zone
Intelligence Plane
Cloud, private cloud, or on-prem
Control Plane
Signed Test Capsule
Customer Transfer Boundary
Customer-controlled segment
Execution Plane
Enclave Gateway
Edge Runner
Target Applications
Local Evidence Store
Optional Sanitized Egress
Approved planning zone
Intelligence Plane
Cloud, private cloud, or on-prem
Control Plane
Signed Test Capsule
Customer Transfer Boundary
Customer-controlled segment
Execution Plane
Enclave Gateway
Edge Runner
Target Applications
Local Evidence Store
Optional Sanitized Egress
Compare deployment models
| Deployment model | Where AI planning runs | Where execution runs | Internet requirement | Data egress model | Ideal use case | Sales motion | Pricing |
|---|---|---|---|---|---|---|---|
| Zof Cloud | Zof Cloud | Zof-managed or customer runners | Standard outbound | Customer-configured | Cloud-native teams, lower-friction pilots | Self-serve to enterprise | Published tiers + enterprise |
| Zof Private Cloud | Dedicated private cloud | Customer-controlled runners | Policy-controlled outbound | Local-first; optional approved egress | Regulated industries, residency requirements | Enterprise sales | Custom, contact sales |
| Zof Hybrid Enclave | Cloud or private cloud | Enclave gateway + edge runners | Not required in protected segment | Local-only default; optional sanitized | Banks, insurance, internal-only apps | Secure deployment briefing | Custom, contact sales |
| Zof On-Prem Control Plane | Customer data center | Customer-managed runners | Optional / air-gapped supported | Local-only typical | No internet, strict residency, internal governance | Architecture review required | Custom, contact sales |
| Zof Local Edge Runner | Paired control plane | Branch, factory, edge site | Not required for execution | Local evidence; optional sync | Distributed sites, segmented networks | Add-on to enterprise deployment | Custom, contact sales |
Secure deployment pricing depends on model, footprint, and implementation scope. View enterprise deployment pricing
Explore deployment options
Secure enclave
Signed capsules, enclave gateway, and local edge runners for segmented and restricted networks.
Private cloud
Dedicated Zof environment in a customer-approved region with stronger isolation and residency controls.
On-prem control plane
Customer-managed infrastructure for strict residency, air-gapped, or limited-connectivity requirements.
Local edge runner
Distributed validation at branch, factory, or edge sites, without exposing local systems to the internet.
Banking secure enclave
Governed validation for core banking workflows through customer-controlled execution and audit-ready evidence.
Plan your deployment with Zof
Walk through architecture, evidence controls, and a conservative pilot path with our deployment specialists.
Continue exploring
Architecture, industry solutions, pricing, and security review resources.
Secure Enclave
Signed capsules and customer-controlled runners for restricted networks
Banking Secure Enclave
Governed validation for core banking workflows
Enterprise Deployment Pricing
Private cloud, on-prem, enclave, and edge pricing
Security Review Checklist
Procurement-ready deployment review checklist
