Service 3: Managed deployments

Sovereignty as a service. You get the control of running it yourself without having to staff a security-operations team. We operate the systems we built for you, or systems you already have. Everything we do is attested and logged, and you can leave at any time.

The rules we operate by

  • You hold the root keys. We work through scoped, time-limited, logged access that you can revoke at any moment.
  • No standing admin access to your data. Where the deployment runs in enclaves, secrets are released only to attested workloads, never to our operators.
  • Every operator action lands in an immutable log that you can verify without trusting us.
  • Exit anytime. The code, infrastructure-as-code and runbooks are already yours. Leaving is a handover, not a migration project.

Where it runs

  • On your premises. Your servers and GPUs, including air-gapped sites. We ship signed updates, and you approve and import them.
  • In colocation. Hardware we sourced for you, racked in a facility in your chosen jurisdiction. See GPUs, hardware and colocation.
  • In your cloud account. AWS, Azure or GCP, using confidential VMs and confidential GPUs where the region supports them.
  • Hybrid. Sensitive steps on your hardware, with bursts to attested confidential capacity.
  • In our confidential capacity. Attested enclaves we operate, in the jurisdiction you choose. The attestation proves that we can't read what runs inside.

See Deployment models for the trust trade-offs of each.

Plans

EssentialsAssuredSovereign
Price$2,500 / month$7,500 / monthCustom
Deployments1 production environmentUp to 3 environmentsUnlimited, including air-gapped
Support hoursBusiness hours (Pacific), next-business-day response24/7, 1-hour response on critical incidents24/7 with a named engineer
Patching and upgradesMonthlyWeekly, emergency patches within 24 hCustom windows
Attestation monitoringMonthly attestation reportContinuous, with alerts on any measurement changeContinuous, with customer-held verifiers
Immutable log retention1 year7 years, WORM storageYour policy, your storage
TCB reviewQuarterlyMonthlyMonthly, plus change review
Incident responseBest effortIncludedIncluded, plus tabletop exercises
Compliance evidence pack—QuarterlyOn demand

GPU and cloud infrastructure costs are passed through at cost, or billed to your own account. All plans are month to month after the first three months.

What "managed" includes

  • Deployment and upgrades with reproducible, signed releases. The measurement changes only when the code does.
  • Attestation monitoring. If a running workload's measurement ever drifts from the pinned release, you hear about it.
  • Log custody. Checkpoints are anchored outside our control (see Immutable logs).
  • Vulnerability management for the OS, dependencies and model runtimes
  • Model operations for AI deployments: model updates, eval regression runs and capacity planning
  • Backups and disaster recovery, encrypted with your keys and tested quarterly
  • Monthly reports covering what changed, what was attested and what we'd fix next

Book a free call to plan a managed deployment.

Talk to a security expert, free. 30 minutes, no slides. Bring the thing that worries you most.
Book a call

© 2026 Yaya Tech PBC · Palo Alto, California · serving clients worldwide · andre@yaya.tech · Privacy · Terms