Cup'n'String
Join Waitlist

© 2026 Cup'n'String

Self-Hosted & Sovereign

Self-Hosted AI Agent Control Plane

For organizations with strict compliance, sovereign data, or high-security requirements, Cup’n’String offers a Standalone Enterprise Edition that runs entirely inside your private cloud or on-premises network.

Why this matters

AI governance data is sensitive: it includes policy logs, audit evidence, and credentials. Many organizations require that this data never leaves their environment.

Policy logs and audit evidence must stay in your environment
Cryptographic keys and keystores must remain under your control
Database telemetry should not leave the network boundary
Sovereign and regulated environments require on-premises operation
Some networks are air-gapped or tightly egress-controlled

The Cup’n’String approach

Cup’n’String is packaged for standard container platforms so it can run inside your infrastructure with your controls.

Standalone Enterprise Edition runs in your private cloud or on-premises
Policy logs, keys, and telemetry stay under your control
Outbound-only agent transport avoids inbound port exposure
Integrates with enterprise identity (SSO/OIDC/SAML) and SCIM provisioning
Supports egress-restricted and sovereign deployment patterns

How it works

  1. Step 1Your infrastructure (private cloud / on-prem)
  2. Step 2Cup’n’String control plane
  3. Step 3Enrolled Desktop Agents
  4. Step 4Policy, shielding & firewall orchestration
  5. Step 5Audit evidence under your control

Checklist

  • Can the control plane run inside your environment?
  • Do policy logs and keys stay under your control?
  • Does agent transport avoid inbound ports?
  • Does it integrate with your identity provider?
  • Can it operate in egress-restricted networks?
  • Can you produce audit evidence locally?

Frequently asked questions

Does Cup’n’String offer on-premises or private cloud deployment?
Yes. The Standalone Enterprise Edition is packaged for standard container platforms and runs entirely inside your private cloud or secure on-premises network, keeping policy logs, cryptographic keys, and database telemetry under your control.
Does it integrate with enterprise identity?
Yes. It includes an Enterprise Identity plane that federates with major identity providers such as Okta, Microsoft Entra ID, and Ping Identity via SAML 2.0 or OIDC, and supports SCIM v2 provisioning.
How do agents connect without inbound ports?
Agents establish secure outbound-only transport (gRPC/WebSocket over TLS), so no inbound ports need to be opened on workstations.
Can it run in restricted-egress environments?
Yes. Cup’n’String supports sovereign and egress-restricted deployment patterns.

Run AI agent governance in your own environment

Keep policy, audit, and credentials under your control with a self-hostable control plane.

Related pages