Private Cloud Deployment
Private Cloud is an enterprise offering. It is not self-service and is not provisioned automatically. Contact the OpsWorker team to discuss whether it fits your requirements.
Overview
OpsWorker deployed within your own AWS account, so all data stays in your infrastructure. This option is for organizations with data residency or sovereignty requirements that the default SaaS deployment cannot meet.
How It Works
| Component | Where It Runs |
|---|---|
| Investigation engine | Your AWS account |
| Data storage | Your AWS account |
| Portal | Your AWS account |
| AI models | AWS Bedrock in your account (Amazon Nova and Claude) |
| Kubernetes Agent | Your clusters |
The Kubernetes Agent behaves the same as in SaaS: read-only (built-in view role), outbound-only, and communicating over SQS with an assume-role credential.
What It Offers
- Data sovereignty. Investigation data stays within your infrastructure.
- Region selection. Deploy in your preferred AWS region.
- Configurable retention. Data retention can be set to match your policies.
- Network isolation. Data does not traverse shared OpsWorker infrastructure.
Considerations
- Requires AWS infrastructure in your account, with OpsWorker support.
- Longer setup time than self-service SaaS.
- Infrastructure costs are borne by the customer.
Best For
- Organizations with strict data residency requirements
- Regulated industries (finance, healthcare) with compliance mandates
- Teams that need OpsWorker data to remain in their own account
Getting Started
This deployment is arranged directly with the OpsWorker team. Contact OpsWorker to plan the deployment. The team will scope your requirements (region and retention), deploy OpsWorker into your AWS account, and provide ongoing support and updates.
Next Steps
- SaaS Deployment is the default model
- Dedicated AWS is a single-tenant alternative (available on request)
- Security & Compliance covers the security architecture