atmon Enterprise

Beta Built 2026-08-07

Deployment models

Four ways to run it.
Three of them on your machines.

A setup on our cloud that your organization is alone in. Or your own cloud account, a private subnet with no public entrance, or a machine on your own floor. The software is the same in all four; the boundary moves.

A pegboard where each tool has one outlined place and one tool sits inside its outline in terracotta: four places a deployment can sit, and one of them is the one your policy already allows.

The four

Pick the one your policy already allows

The first column is the offer we run for you. The other three are the same software on machines you own, and what separates those three is where the machine sits and how your people reach it.

 On our cloudYour cloudYour private subnetYour building
Whose machineOurs, and your organization is alone on itAn account you own, in the region you chooseA subnet with no route in from the internetA server on your own floor
Who operates itWe doYour team, under your change process
Where people sign inenterprise.atmon.ai/console, with an emailYour usual entrance for an internal web toolOver the network your staff already useThe office network
Who holds the key over the storeWe do, and no path reads a secret back outYou generate it, you hold it, and no path reads a secret back out
What has to be openNothing. Your people reach it in a browserOutbound to the apps you listed
What we can reachThe machine we run for youNothing
Where the record livesOn the node we run, exported from your consoleA table in your own database

If the apps a department works in are themselves internal, the relay is how either offer reaches them, and it dials out from your side in both.

On our cloud

Where a hosted setup sits

One node, running your organization's work and nobody else's. Your people and your assistants reach it from your own network, and it reaches the apps you connected on your behalf.

A dashed terracotta boundary holds the setup we run for your organization: one node it is alone on, its records, and the store its credentials are sealed in. Your people at the console and your assistants dial into it from your own network, and the node reaches the apps your teams use outbound, over the addresses you listed. From your network Your people the console in a browser Your assistants and your own services they dial in Your setup, on our cloud atmon a node your organization is alone on Your records every action,yours to export The store sealed under ourdeployment key Outside your setup The apps your teams use reached outbound, overthe addresses you listed
The dashed line is the boundary of what is your organization's alone. On this model it sits around a machine we run, and that is the difference between this offer and the three under it.

In your building

What runs where, on your own machines

Everything with your name on it sits inside your perimeter. Two lines cross the boundary and both are outbound.

A dashed boundary labelled your network holds four boxes: your people at the console, atmon running as one process on your machines, your records in your own database, and your key. Two arrows leave the boundary: one to the apps your teams use, reached outbound over the addresses you listed, and one to atmon the company, carrying a signed count of the actions you took. Your network Your people the console in a browser atmon one process, on your machines Your records every action,in your database Your key seals everystored secret Outside your network The apps your teams use reached outbound, overthe addresses you listed atmon, the company a signed count of theactions you took
The terracotta line is the only thing we ever receive, and it carries counts and a signature. The ink line is your own traffic to the apps you connected, which goes out from your network and not from ours.

Internal systems

Reaching something with no public address

Plenty of the systems a department lives in have no address on the internet: the warehouse system, the claims desk, the thing written in 2009 that finance will not give up. Either offer reaches those through a relay.

Two dashed boundaries. On the left, where atmon runs: our cloud, your cloud account, or your own machine. On the right, your office network, holding the relay and, under it, your internal system with no public address. The relay dials out to atmon, and work travels back down the same connection, so nothing inbound is opened on either side. Where atmon runs atmon our cloud, your cloud account, or your machine Your office network The relay runs beside the system it fronts Your internal system no public address the relay dials out work travels back
The relay opens the connection from your side. Neither network accepts anything inbound for this to work, and the relay holds its own identity, so revoking it stops that one path and nothing else.

Running it yourself

What your team operates, in your building

On our cloud this section is our work rather than yours. On your own machines it is a process, its files under one directory, started with one secret. That shape comes with one hard rule: two processes writing the same files from two machines is data loss rather than resilience.

For most deployments that is the right trade. One machine with continuous backup and a restore your team has actually practised comes back in minutes.

What it does not give you is staying up through a reboot, so an upgrade is a short announced window rather than a rolling one.

An open bound booklet, ruled on both leaves, with a terracotta ribbon marker out of the spine: the operator guide your team runs the deployment from.

The short list

What a deployment on your machines never asks for