NEW  AI investigations now open fix PRs automatically — see what's new →
Security & trust

Self-hosted, so security says yes faster.

oneinfra was built for teams who can't send production telemetry to someone else's cloud. Everything runs in your environment, under your controls.

SOC 2 ready TLS 1.3 · AES-256 SSO / SAML · RBAC Air-gap capable
Architecture

What actually runs in your cluster

No external control plane. No vendor data plane. Just two pods + your existing telemetry sources + the LLM provider you already use.

YOUR KUBERNETES CLUSTER No data leaves this box without your explicit config YOUR EXISTING STACK ⊙ Prometheus ⊙ Alertmanager ⊙ Loki / Elasticsearch ⊙ Kubernetes API ⊙ eBPF / service mesh ⊙ GitHub / GitLab ⊙ PagerDuty / Slack oneinfra-agent pod · 100m CPU · 128Mi RAM reads-only by default writes via explicit RBAC oneinfra-control-plane pod · 500m CPU · 512Mi RAM SQLite + 1Gi PV serves UI on :80 Your browser Auth: SSO / SAML / RBAC All traffic stays in your network Your LLM provider OpenAI · Anthropic · Bedrock Azure · Ollama · vLLM YOUR API key, your bill, your data-handling terms only egress · prompts only

Footprint per cluster

ComponentCPU requestMemoryStorageReplicas
oneinfra-agent100m128Mi1 (HA: 3)
oneinfra-control-plane500m512Mi1Gi PV1 (HA: 3 + Postgres)
Total (single-replica)600m640Mi1Gi

Telemetry the agent reads (Prometheus, logs, K8s API) is whatever you already run — no additional storage required from oneinfra.

Controls in depth

What your security team will ask about

Runs in your VPC

The entire platform — agent, control plane, and AI — deploys inside your own network. There is no oneinfra cloud in the data path.

No data egress

Telemetry, logs, and investigation results stay within your perimeter. Enterprise supports fully air-gapped operation with a self-hosted LLM.

Read-only by default

The agent observes with scoped, auditable permissions. No application data is extracted; remediations are explicit and guarded.

Encryption everywhere

TLS 1.3 in transit and AES-256 at rest, with your own keys in Enterprise deployments.

SSO, SAML & RBAC

Enterprise identity, role-based access control, and full audit logging of every action and AI investigation.

Bring your own model

Use OpenAI, Anthropic, AWS Bedrock, or a local model. Your prompts and context are never used to train third-party models.

The difference

SaaS AI-SRE tools ask you to trust their cloud. oneinfra doesn't ask.

Because nothing leaves your network, oneinfra clears the reviews that stall hosted competitors — data residency, vendor risk, and egress are simply not on the table.

  • No third-party data processorYour telemetry is never sent to a vendor for processing.
  • Your keys, your modelRun a local LLM for fully offline investigations.
  • Full audit trailEvery query and AI action is logged and exportable.

Bring it to your security team.

We'll walk through the architecture, deployment model, and controls in detail.

Explore the app →
Talk to us

A 15-min conversation. No calendar tango.

Drop your details, we reply within 4 business hours.