New:System Graph 2.0See System Graph 2.0
Deployment

Customer-controlled execution for every environment

Zof generates governed test intelligence, packages signed capsules, and executes through customer-controlled runners, without requiring protected applications to call external AI services.

No inbound access required · No external model calls from protected networks · Signed test capsules

No inbound access required

No external model calls from protected networks

Signed immutable test capsules

Human approval for governed remediation

Deployment models

Execution near your environment, governance by design

Cloud is one path—not the only path. Zof is designed for enterprises that require customer-controlled execution, segmented networks, and regulated operating models.

  • Cloud-managed and dedicated private cloud control planes
  • Customer VPC/VNet execution with outbound-only connectivity patterns
  • Hybrid architectures combining public cloud orchestration with local execution
  • Edge runners and endpoint agents for branch, factory, and desktop validation
  • Enclave-style execution with signed capsules and controlled telemetry egress
  • Private Kubernetes-compatible execution in customer-managed clusters
Reference architecture

Three planes. One governed execution model.

Intelligence and control stay where policy allows; execution stays inside your boundary. Sensitive data remains in the execution plane unless you approve egress.

Intelligence Plane

Governed test intelligence

Planning, generation, and prioritization run where policy permits, Zof Cloud, private cloud, or on-prem.

  • -System Graph and workflow understanding
  • -Risk prioritization and test generation
  • -Signed capsule assembly
  • -Remediation planning where permitted
  • -No direct execution against protected apps from external SaaS

Control Plane

Approvals and policy

Customer-governed layer for signing, scheduling, audit trails, and evidence routing.

  • -Human approval workflows
  • -Cryptographic signing and policy enforcement
  • -Capsule versioning and promotion
  • -Role-based access and SSO integration
  • -Audit-ready records for every action

Execution Plane

Customer-controlled execution

Tests run inside your infrastructure. Sensitive data stays inside unless you approve egress.

  • -Local edge runner execution
  • -Browser, API, and desktop validation
  • -Local evidence capture and redaction
  • -Optional sanitized or metadata-only egress
  • -No external model calls from protected networks at runtime

Secure enclave architecture

Intelligence and control operate outside the protected segment; execution and evidence stay inside via signed capsules and customer-controlled runners.

Approved planning zone

Intelligence Plane

Cloud, private cloud, or on-prem

Control Plane

Signed Test Capsule

Customer Transfer Boundary

Customer-controlled segment

Execution Plane

Enclave Gateway

Edge Runner

Target Applications

Local Evidence Store

Optional Sanitized Egress

Compare deployment models

Compare where planning runs, where tests execute, and how evidence may leave your boundary. Models can be combined in hybrid topologies.

Deployment modelWhere AI planning runsWhere execution runsInternet requirementData egress modelIdeal use caseSales motionPricing
Zof CloudZof CloudZof-managed or customer runnersStandard outboundCustomer-configuredCloud-native teams, lower-friction pilotsSelf-serve to enterprisePublished tiers + enterprise
Zof Private CloudDedicated private cloudCustomer-controlled runnersPolicy-controlled outboundLocal-first; optional approved egressRegulated industries, residency requirementsEnterprise salesCustom, contact sales
Zof Hybrid EnclaveCloud or private cloudEnclave gateway + edge runnersNot required in protected segmentLocal-only default; optional sanitizedBanks, insurance, internal-only appsSecure deployment briefingCustom, contact sales
Zof On-Prem Control PlaneCustomer data centerCustomer-managed runnersOptional / air-gapped supportedLocal-only typicalNo internet, strict residency, internal governanceArchitecture review requiredCustom, contact sales
Zof Local Edge RunnerPaired control planeBranch, factory, edge siteNot required for executionLocal evidence; optional syncDistributed sites, segmented networksAdd-on to enterprise deploymentCustom, contact sales
Customer VPC / VNetCloud or private cloudCustomer VPC runnersOutbound-only typicalLocal-first; policy-controlledEnterprise SaaS in your cloud accountArchitecture reviewCustom, contact sales
Private Kubernetes executionCustomer-approved control planeCustomer-managed cluster agentsPolicy-controlledNamespace-scoped evidencePlatform teams with existing K8s estatesArchitecture reviewCustom, contact sales
Endpoint agentsPaired control planeDesktop / VDI / legacy UIOutbound registration typicalLocal capture; optional sanitizedERP, Citrix, internal desktop appsEnterprise deploymentCustom, contact sales

Secure deployment pricing depends on model, footprint, and implementation scope. View enterprise deployment pricing

Enterprise governance

Control planes, approval workflows, and audit evidence

Deployment flexibility is paired with governed autonomy: human approval, least-privilege access, and evidence routing you define.

Remediation approval workflow

Governed path from detection to verified fix.

DetectProposeApproveApplyVerifyAudit
  • Role-based access, SSO, and separation of duties for capsule promotion
  • Human approval before governed remediation in production paths
  • Configurable evidence modes: local-only, sanitized, or metadata-only
  • Audit trails for planning, execution, approvals, and administrative actions
Representative scenarios

How regulated enterprises deploy Zof

Anonymized industry models illustrating deployment approaches in similar environments. Not endorsements or customer identifications.

This representative scenario is an anonymized industry model used to explain how Zof AI can be deployed in similar enterprise environments. It does not identify or imply a specific customer relationship.

Regulated advisory environment

Client data and internal advisory systems cannot be exposed to public SaaS execution.

Infrastructure constraints
Strict residency, no unmanaged external AI calls from advisory networks.
Network segmentation
Separate VLANs for client-facing apps, research tools, and admin systems.
Deployment architecture
Private cloud control plane with enclave gateway and local runners.
Endpoint / edge execution
Edge runners validate internal portals; endpoint agents for desktop workflows.
Governance controls
Capsule signing, dual approval for production remediation, full audit export.
Telemetry boundaries
Metadata-only egress to central dashboards; raw evidence stays local.
Remediation governance
PR-based fixes with human authorization; no silent production changes.

Payment processing environment

Cardholder data environments require segmented execution and controlled egress.

Infrastructure constraints
PCI-aligned segmentation; least-privilege runner placement.
Network segmentation
CDE-isolated segments with dedicated gateways per zone.
Deployment architecture
Hybrid: cloud planning in approved region, execution in customer VPC.
Endpoint / edge execution
Kubernetes-compatible agents in customer clusters; API validation in VPC.
Governance controls
PAM-brokered credentials, signed runners, change-control integration.
Telemetry boundaries
Sanitized egress with field masking; retention per compliance program.
Remediation governance
Staging-first remediation with verification suites before promotion.

Manufacturing operations environment

Plant-floor and MES systems need local validation without internet exposure.

Infrastructure constraints
OT/IT boundaries, intermittent connectivity, latency-sensitive checks.
Network segmentation
Factory networks isolated from corporate cloud control planes.
Deployment architecture
Central orchestration with distributed edge runner fleet per site.
Endpoint / edge execution
Edge runners at plants; optional outbound-only sync for capsule updates.
Governance controls
Site-level policies, fleet inventory, and local evidence bundles.
Telemetry boundaries
Local-only reporting default; optional aggregated health metadata.
Remediation governance
Human approval for changes affecting production lines.

Identity and trust environment

Identity platforms require high-assurance testing inside trust boundaries.

Infrastructure constraints
Secrets and tokens must not leave execution plane unredacted.
Network segmentation
DMZ, internal service mesh, and admin tooling on separate paths.
Deployment architecture
Customer VPC execution with secure enclave patterns for privileged flows.
Endpoint / edge execution
API and browser validation in VPC; endpoint agents for admin consoles.
Governance controls
Short-lived credentials, execution allowlists, continuous audit.
Telemetry boundaries
Evidence sanitization before any cross-zone transfer.
Remediation governance
Governed remediation with rollback verification in staging.

Enterprise systems integration environment

SI programs connect ERP, CRM, and custom middleware across hybrid estates.

Infrastructure constraints
Multi-region customers, mixed cloud and on-prem endpoints.
Network segmentation
Per-tenant or per-project network boundaries for validation workloads.
Deployment architecture
Hybrid cloud reliability: cloud control plane + VPC and on-prem runners.
Endpoint / edge execution
Distributed testing fleets targeted via System Graph change impact.
Governance controls
Project-scoped policies and evidence routing per engagement.
Telemetry boundaries
Configurable per environment; central analytics where approved.
Remediation governance
Approval workflows aligned to customer CAB processes.

Healthcare administration environment

Administrative systems handling PHI require residency-aware execution.

Infrastructure constraints
HIPAA-aligned handling; minimize data movement outside boundary.
Network segmentation
Clinical vs administrative network separation.
Deployment architecture
Private cloud or on-prem control plane with local execution workers.
Endpoint / edge execution
Internal-only application testing; desktop agents for legacy admin UIs.
Governance controls
Retention policies, access reviews, and breach-ready audit exports.
Telemetry boundaries
Local-first evidence; metadata summaries for enterprise dashboards.
Remediation governance
Human-in-the-loop for changes touching PHI workflows.

Security operations environment

Security tooling and SOAR-adjacent workflows demand isolated validation.

Infrastructure constraints
High sensitivity logs and configs; no inbound access to SOC segments.
Network segmentation
SOC VLAN, tool integrations, and staging mirrors of production.
Deployment architecture
Enclave-style execution with signed packages and restricted outbound.
Endpoint / edge execution
Runners in SOC segment; API validation for integrations and playbooks.
Governance controls
Immutable capsules, approval chains, integration with GRC tooling.
Telemetry boundaries
Controlled telemetry egress with evidence sanitization.
Remediation governance
Verified fix workflows with security sign-off gates.

This representative scenario is an anonymized industry model used to explain deployment approaches in similar enterprise environments. It does not identify a specific customer.

Architecture reference

Enterprise deployment topologies

Representative diagrams for common buyer review scenarios. Your architecture review will define the exact placement of each plane.

Cloud-managed architecture

Zof-managed control plane with configurable execution placement.

Zof Cloud (customer tenant)Control planePolicies & approvalsOrchestrationExecutionManaged or customer runnersEvidence store

Customer VPC execution

Planning in approved cloud; execution inside your VPC boundary.

Customer VPC / VNetCustomer networkControlIntelligenceTransfer gatewayExecution agentApplications

Hybrid execution architecture

Cloud orchestration with distributed local execution fleets.

Cloud / private cloudCustomer execution estateControlIntelligenceVPC runnerEdge runnerEndpointOn-prem runner

Edge runner topology

Local execution with centralized orchestration.

Control planeGatewayEdge runnerAppsLocal evidence

Endpoint agent topology

Desktop and legacy application validation via customer-deployed agents.

Control planeOrchestrationEndpoint agentDesktop / VDILocal evidence

Secure enclave execution

Segmented execution with signed capsule transfer.

Approved planning zoneProtected segmentIntelligenceControlGatewayRunnerAppsEvidence

Private Kubernetes execution

Execution-compatible agents in customer-managed clusters—not a full platform install.

Control plane (customer or Zof)Customer Kubernetes clusterControl planeSignNamespaceExecution agentWorkloadsSecretsArtifactsTelemetry boundary

Distributed testing fleets

Multiple fleets orchestrated from a central control plane.

Control planeFleet AFleet BFleet CFleet D

Remediation approval workflow

Governed path from detection to verified fix.

DetectProposeApproveApplyVerifyAudit

Telemetry flow

Runner capture through optional controlled egress.

RunnerLocal storeRedactionApproved egress

Evidence routing

How validation artifacts may leave the execution boundary.

CaptureLocal onlySanitizedMetadata only
Next step

Plan your deployment with Zof

Walk through architecture, evidence controls, and a conservative pilot path with our deployment specialists.

01Lumahing operasional

Siji lumahing kanggo dedeg piadeg, operasi, lan apa perlu manungsa waé sabanjuré.

Omah Zof dudu dashboard marketing. Iki minangka teknik permukaan operasional, QA, lan tim SRE sing digunakake saben dina, postur kualitas, mlaku ing pesawat, jangkoan miturut modul, lan tumindak sing kudu ditindakake pimpinan sabanjure.

KPI OPERASIONAL

  • Runs
  • Cakupan
  • Resiko

Urip ing saben lingkungan sing dikirim.

KARYA TULANG BELAKANG

  • Spesifikasi
  • Tes
  • Jadwal

Saka specification kanggo regresi dijadwal.

GUARDRAILS

  • RBAC
  • SSO
  • audit

Saben tumindak sing digandhengake karo manungsa sing jenenge.

STAGING · LIVE/home
Pusat komando ngarep Zof AI nuduhake 12 mlaku ing 94% pass, 3 mbukak masalah kritis, 84% jangkoan, papat modul traceability bar, pipeline specification, jadwal mbesuk, lan dianjurake tumindak sabanjuré karo sidebar aktif-mlaku.
Tampilan ngarep · Layanan Checkout · Pementasan · dijupuk langsung saka produk.
  • 01 · RUNS · 24H

    94% pass

    12 runs across staging

  • 02 · COVERAGE

    84%

    Across four modules

  • 03 · ACTIVE RUNS

    3 running

    Live on this branch

  • 04 · NEXT ACTIONS

    Recommended

    Triage gaps, new spec

Zof AI Deployment Options, Secure, Private Cloud, On-Prem, and Edge