Architecture · Deployment

Where it runs is your choice.

These are the most common ways FabriCloud is deployed. The control-plane / data-plane split is elastic — the fabric, enrichment and agents can run wherever your sovereignty, latency and cost constraints put them — so many more configurations are possible than the three shown here.

01Self-hosted

Everything — control plane, fabric, enrichment and agent execution — runs inside your environment. FabriCloud is software in the data path only insofar as you run it; the vendor cloud is optional (updates / licensing) and air-gapped operation is supported. Maximum sovereignty, highest operational burden.

CONSUMERS BI & Dashboards Applications AI Agents · MCP FabriCloud SaaS — optional (updates / licensing only) FabriCloud SaaS — not in the data path optional: software updates · licensing · air-gap supported YOUR ENVIRONMENT — NO RAW DATA LEAVES nothing in the data path · optional telemetry / updates only Your Environment — your cloud / VPC / on-prem Everything runs inside your environment — control plane, fabric, enrichment and agents Control Plane self-hosted Fabric / Graph ER · KG · catalog Enrichment entities · OSINT Agent Scheduler + runtime · L0–L4 AGENTS RUN HERE Data Plane compute · indexes Sources — read / written in place Databases Warehouses Lakes Streams SaaS / Apps

02Remote fabric · local agent execution

The control plane and agent scheduler are managed in the cloud (metadata only), but the fabric, enrichment and the agent runtime stay in your environment — agents execute next to the data. You get managed operations while keeping all compute and data in-boundary.

CONSUMERS BI & Dashboards Applications AI Agents · MCP FabriCloud — Managed Control Plane (Cloud) · metadata only Policy · Identity governance Gateway MCP · GraphQL · REST Catalog / Metadata active metadata Agent Scheduler plan · registry Observability audit · SIEM YOUR ENVIRONMENT — NO RAW DATA LEAVES metadata · control signals · agent plans ↓ · telemetry ↑ — no raw data Your Environment — your cloud / VPC / on-prem FabriCloud Data Plane — fabric, enrichment AND agent execution stay in your env Data Plane compute · indexes Fabric / Graph ER · KG · vectors Enrichment entities · OSINT Agent Runtime agents EXECUTE here L0–L4 Local Policy enforce at source Sources — read / written in place Databases Warehouses Lakes Streams SaaS / Apps

03Cloud fabric · cloud enrichment · cloud agent scheduler

The control plane, entity enrichment and agent scheduler/runtime run in the cloud. Your environment keeps the raw data, indexes and graph store; cloud agents and enrichment reach in through the gateway with access enforced at the source, receiving only governed, permissioned results. Lowest ops burden; raw data still never leaves.

CONSUMERS BI & Dashboards Applications AI Agents · MCP FabriCloud Cloud — control plane + enrichment + agent scheduler & runtime Control Plane policy · identity · gateway Catalog / Metadata active metadata Enrichment Service entities · OSINT Agent Scheduler + runtime AGENTS RUN IN CLOUD Observability audit · SIEM YOUR ENVIRONMENT — NO RAW DATA LEAVES metadata · control · governed/permissioned results — raw data stays in env Your Environment — your cloud / VPC / on-prem Your Environment keeps raw data, indexes and the graph store — queried via the gateway Data Plane raw data · indexes Fabric / Graph store ER · KG · vectors Gateway PEP enforced at source Network mTLS · outbound-only Sources — read / written in place Databases Warehouses Lakes Streams SaaS / Apps
At a glance
Option 1 — Self-hostedOption 2 — Remote fabric, local agentsOption 3 — Cloud fabric & cloud agents
Control planeIn your env (self-hosted)Managed (cloud)Managed (cloud)
Fabric / graph storeIn your envIn your envIn your env
Entity enrichmentIn your envIn your envIn cloud (via gateway)
Agent schedulerIn your envCloudCloud
Agent executionIn your envIn your envIn cloud (queries via gateway)
Crosses the boundaryNothing (telemetry / updates only)Metadata · control · agent plansMetadata · control · governed results
Raw data egressNoneNoneNone (results only, enforced at source)
Ops burden on youHighestLow (managed control plane)Lowest
Sovereignty / air-gapMaximum · air-gapHighHigh (data stays; compute reaches in)
Best whenStrict isolation, air-gapped estatesYou want managed ops but agent compute next to dataMinimal ops; elastic cloud agents over governed context

Mix and match per environment, per region, per workload. In every configuration the boundary holds: no raw data leaves.