Architecture
Your estate. Your network. Your control.
Opencontroller runs inside your trust boundary and governs AI wherever it runs, across clouds, private infrastructure and developer devices.
One control plane. Many runtimes.
Choose where control lives. Keep your agents, models, tools and enterprise systems where they already run.
- Kubernetes / managed agents
- Customer-owned data services
- Private connectivity
- Kubernetes / managed agents
- Customer-owned data services
- Private connectivity
- Kubernetes / managed agents
- Customer-owned data services
- Private connectivity
- Your Kubernetes / hardware
- Your model endpoints
- No public internet dependency
Fits the stack you already own.
Opencontroller adds agent-specific control without asking you to replace the enterprise systems already doing their jobs.
Identity stays here.
Your IdP remains the source of truth for people and access.
CI stays here.
Your pipeline still builds, scans and signs the artifacts.
Secrets stay here.
Provider credentials remain inside your approved secret manager.
Traces stay here.
OpenTelemetry continues into the collectors you already operate.
Agents stay here.
Existing frameworks and runtimes remain untouched.
Control gets added here.
Opencontroller becomes the governed front door in front of AI activity.
Open by design.
Connect through standards your developers and infrastructure already understand. No platform-specific agent SDK required.
Change an endpoint. Not your application.
Control happens in the path.
Every governed action can be authenticated, authorized, budgeted and checked before it reaches a model, tool or enterprise system.
Who is acting, and for whom?
Is this action allowed?
Can this request spend?
PII, secrets, injection, policy.
What can it reach?
Provider, fallback, cache.
Trace, outcome, cost, verdict.
One policy. Wherever AI runs.
Use a single control layer across multiple clouds, private infrastructure and managed agent runtimes without centralizing the workloads themselves.
Cloud environment
Cloud environment
Cloud environment
On-prem / edge
Control travels. Workloads, application data and local services stay in the environments you choose.
Sovereignty by architecture.
Keep control-plane data, credentials, telemetry and deployment inside the boundaries you define. External traffic goes only to destinations you authorize.
Registry, policy, approvals and evidence.
Identity, budgets, guardrails and routing.
Resolved from your approved secret store.
Exported to collectors and stores you control.
Model providers, MCP servers, enterprise systems or self-hosted endpoints you explicitly permit.
Your compute
Deploy in your cloud, private infrastructure or your own hardware.
Your network
Use private connectivity and enterprise-controlled egress paths.
Your credentials
Provider secrets do not need to be distributed to individual agents.
Your evidence
Keep traces, audit records and evidence bundles in stores you control.
The control surface starts before production.
Basecode extends visibility and policy to supported developer devices and coding agents, then carries that control model into CI and production.
Basecode
Usage, policy, tool access, spend and approved-stack controls.
Opencontroller
Registry, release gates, runtime policy and evidence.
Production
Cloud, private and on-prem agent runtimes under the same control model.
From the laptop to the runtime.
Your pipeline stays your pipeline.
Opencontroller governs the handoff into production. Your CI continues to build, scan and sign the artifacts you deploy.
Change enters your repo.
Build · scan · sign.
Your artifact stays yours.
Evaluate · approve · record.
Promote using your process.
Deploy where the workload belongs.
The questions your architects will ask.
No. Agents continue to run in the environments and runtimes you already use. Opencontroller adds a control and governance layer around them.
It can run inside your cloud account, private infrastructure or on-prem environment. Fully air-gapped deployments are supported where external connectivity is not permitted.
Yes. A central Opencontroller deployment can govern agent environments across cloud and private infrastructure while workloads remain in their existing locations.
No. Opencontroller uses standard interfaces including OpenAI-compatible APIs, MCP, A2A, OpenTelemetry, SAML/OIDC/SCIM, REST and webhooks.
No. It complements them with agent-specific identity, policy, release, model/tool control and evidence while integrating with the systems you already operate.
Not in customer-managed deployment modes. The control plane and gateways can run inside your environment. External traffic goes only to the model, tool or system destinations you explicitly authorize.
In customer-managed deployments, Opencontroller does not require your control-plane telemetry, credentials or application evidence to be exported to Lyzr. Your deployment and retention model remain under your control.
Yes. Your CI can continue to build, scan and sign artifacts. Opencontroller applies lifecycle events, evaluations, approvals and release controls around the deployment handoff.
Provider credentials can stay in your enterprise secret-management system and be resolved at the enforcement layer rather than distributed to individual agents.
Basecode extends the control surface to supported developer devices and coding agents, bringing relevant agent activity, model usage, tooling and policy signals into the broader Opencontroller estate.
The architecture is designed to avoid lock-in: your code, images, repositories, collectors and infrastructure remain yours. The control layer can be removed without rebuilding the application estate.
Control without moving your estate.
Start with discovery, a gateway or one governed release path. Add the rest when you are ready.