Atlas
Isolated microVM Compute
Hardware-isolated microVMs that run untrusted code and leave nothing behind.
Secure execution capacity in Scaleway-hosted microVMs for AI-native software creation and controlled runtime boundaries. It is built for the work that needs a clean machine every time: testing and evaluation, CI and CD, and AI coding agents that have to be free to run anything without putting a shared host at risk.
- Hardware-isolated microVMs, one per workload, hosted on Scaleway in Europe or on hyperscalers such as Azure, AWS and GCP, and compatible with your own on-prem infrastructure
- Ephemeral preview environments: nothing is persisted once the task ends
- Cost control by construction: a microVM exists only for the length of its task, so there is no idle machine kept warm and nothing is paid for waiting
- Status
- Beta
- Agents
- 1
- Workflows
- 1
Untrusted and AI-generated code executes safely, because nothing shares a kernel and nothing outlives its task.
Vauban
Code Security
End-to-end application security, SAST and beyond, one click from your repository.
Static code security at a level web development has not seen: end to end, and at a more reasonable price than any competitor. Vauban is built for teams that have to keep their code inside their own infrastructure, or inside the borders of one country. It began because no such platform existed in France, or in Europe more widely, and it now runs the same way for any company, in any country, on infrastructure it owns.
- Far more than SAST: SCA, SBOM, AI Security Reviewer and more, one click from your repo
- The same complete offer in the cloud and on your own infrastructure, wherever that infrastructure runs
- Preview environments on Atlas out of the box: analyses run isolated, code is never stored
- Status
- Release Candidate
- Agents
- 3
- Workflows
- 5
A team that cannot let its code leave its own infrastructure still gets complete application security, with nothing given up for the constraint.
Tzu
Policy, Architecture and Audit
Context, plans, governed access to models and audit evidence, decided before the work and proven after it.
Context super-management that turns company policy and architecture into detailed, checkable plans before delivery begins. Systems, decisions and standards are held as one connected memory behind those plans. Tzu also sits in front of every call to a model, keeps the secrets that call needs, and makes its cost visible, so governance, AI access and spend are answered in one place.
- Context super-management: one governed source of plans, standards and decisions
- Knowledge graph: systems, decisions and standards connected behind every plan
- LLM gateway: every call to a model routed, attributed and kept inside your boundary
- Token optimization: caching and context reuse that cut what each run spends
- Secrets custody: strict permission boundaries, so raw credentials never travel with the work
- Audit in depth: governance checked in code and infrastructure, evidence kept as an auditable record
- Status
- Beta
- Agents
- 21
- Workflows
- 34
Every product delivers against a written rule, and the evidence that it did exists without anyone assembling it.
Galileo
Systems, Data and AI Health Monitoring
Synthetic checks, database and AI key monitoring, public status signals and webhook alerts.
Information stewardship for systems and APIs: synthetic checks that exercise real endpoints, journey monitoring that follows a user through the whole web path, and public status signals your customers can read. It also watches what delivery actually depends on: database connection pools, backups and logs, with resize, backup and restore available as actions.
- Synthetic checks and scheduled smoke tests against live systems and APIs
- Web journey monitoring across the whole user path, not a single endpoint
- Database monitoring: connection pool, backups and logs, with resize, backup and restore as actions
- AI API keys watched for liveness, expiry and quota, before a run fails on them
- Model and price tracking, so a provider changing its terms is seen when it happens
- Status health inside and outside the perimeter: status.euphile.eu is Galileo reporting on euphile
- Webhook notifications that tell the next system something is wrong, with no human relay
- Status
- Alpha
- Agents
- 1
- Workflows
- 3
Degradation is seen and stated before customers are the ones reporting it.
Moltke
Scenario and Agentic Simulation
Token forecasts, TCO ranges, VUCA scenarios and agentic simulations, deployable as an API.
Scenario simulation for decisions that are expensive to reverse: token consumption forecasts, total cost of ownership ranges, and purpose-built system dynamics models. It is built for a VUCA world, where the question is how a system behaves across volatile, uncertain, complex and ambiguous conditions rather than along one smooth trend.
- Token consumption forecasts across models, workloads and growth curves
- TCO ranges with the assumptions stated, not a single optimistic number
- System dynamics models built for the specific platform under study
- VUCA scenarios: volatile, uncertain, complex and ambiguous conditions modelled together
- Any model deployable as an API, so your own applications can query it directly
- Agentic simulations: populations you define emit signals into the system, on the default AI provider or your own model (BYOM)
- Status
- Beta
- Agents
- 4
- Workflows
- 0
Architecture and budget decisions are taken against modelled ranges rather than estimates.
Plutus
Legal and Platform Control
Terms, rights, users and subscriptions, run headless as workflows rather than documents.
Headless legal workflows and terms management, with a legal and privacy ontology offered as a service, alongside a user service hosted in the EU. It holds product and user rights, entitlements and payment-provider-backed platform operations for everything the platform sells or grants.
- Headless legal workflows and versioned terms management
- Legal and privacy ontology as a service, queried by the other products
- Product and user rights, entitlements and payment-provider-backed operations
- User service hosted in the EU, with RBAC over access to data and applications
- Feature maps and release maps per product, kept against what actually shipped
- User subscription management: free trial, standard, premium and whatever packaging you configure
- Agentic and headless throughout, so other applications and no-code tools consume it directly
- Status
- Alpha
- Agents
- 25
- Workflows
- 2
What a user has agreed to, is entitled to and has paid for is one governed answer, not three systems.
Leonardo
Deterministic DevSecOps Workflow
Deterministic delivery over governed tools, models and CLI workflows.
Delivery that produces the same result from the same inputs, run over an approved set of tools, models and command-line workflows. It is for teams who need AI inside the pipeline without losing reproducibility or control of what actually ran.
- Deterministic pipelines: the same inputs produce the same artefacts, every run
- Governed access to tools and models, with the chosen versions pinned
- CLI workflows that execute in Atlas microVMs rather than on a developer machine
- Status
- Alpha
- Agents
- 1
- Workflows
- 1
AI-assisted delivery becomes reproducible engineering, auditable step by step.
Nassau
Workstation Security
Security for secure software development starts at the workstation, where the code is written.
Security in a secure development lifecycle has to start at the workstation, on the machine where the code is actually written, not at the pull request. Nassau watches that machine for spyware and hostile traffic, runs SAST, SCA and SBOM locally before anything reaches the repository, and lets a team build and run its own security tooling on top.
- Spy detection and traffic monitoring on the developer machine, with an antimalware bridge in progress
- SAST, SCA and SBOM run on the workstation, before the code reaches the repository
- Build your own security tools, then evaluate, test and run them from the same place
- AI advisory on false positives, so the noise does not train people to ignore findings
- Supply-chain compromise detection on dependencies pulled to the workstation
- Trusted code, configuration and execution context handed on to the platform
- Status
- Beta
- Agents
- 8
- Workflows
- 2
The delivery chain starts from a workstation proven clean, not assumed clean.
Solon
Telemetry and Costs
Analytics, observability and cost measurement, with dashboards you ask for and get.
Analytics, observability and detailed usage reporting for everything the platform runs, with cost measured from the same records. It turns platform behaviour into operational proof rather than opinion.
- Usage analytics and observability across products, agents and workflows
- Detailed reporting attributed to team, workload and environment
- Cost measured from executed work, and checked against Moltke's forecasts
- Dashboards without the build: ask for one over your data and it assembles itself
- Per-event data processors you define, to anonymise or reshape records on ingestion or on a schedule
- Data retention and GDPR compliance built in, not bolted on afterwards
- Status
- Alpha
- Agents
- 14
- Workflows
- 2
Spend and behaviour are stated as measured fact, ready for an operational or financial review.
Richelieu
Application Foundry
Applications made, released and kept alive on one governed platform.
Richelieu makes applications. It manages their whole life: environments, deployments, artefacts and the DevSecOps lifecycle itself. The work underneath belongs to the other products, but a team never has to assemble them. Richelieu holds the state of every application, decides the order of the work, and calls each product at the point where its work belongs.
- Environments and promotion: dev, test and production run as one path, with every deployment and artefact recorded as evidence
- Each stage executed by the product that owns it: plans, specifications and policy in Tzu, implementation in Leonardo, post-deployment monitoring in Galileo, users, payments and legal in Plutus
- Existing applications imported with the pipelines they already use, then maintained through Leonardo and Tzu rather than rebuilt
- Status
- Alpha
- Agents
- 28
- Workflows
- 19
A team owns the whole life of its applications, from environments and releases to artefacts and maintenance, without assembling that discipline out of separate tools.