Atlas
Isolated microVM Compute
Hardware-isolated microVMs that run untrusted code and leave nothing behind.
Secure execution capacity in Scaleway-hosted microVMs for AI-native software creation and controlled runtime boundaries. It is built for the work that needs a clean machine every time: testing and evaluation, CI and CD, and AI coding agents that have to be free to run anything without putting a shared host at risk.
- Hardware-isolated microVMs, one per workload, hosted on Scaleway in Europe or on hyperscalers such as Azure, AWS and GCP, and compatible with your own on-prem infrastructure
- Ephemeral preview environments: nothing is persisted once the task ends
- Cost control by construction: a microVM exists only for the length of its task, so there is no idle machine kept warm and nothing is paid for waiting
- Status
- Beta
- Agents
- 1
- Workflows
- 1
Untrusted and AI-generated code executes safely, because nothing shares a kernel and nothing outlives its task.
Vauban
Code Security
End-to-end application security, SAST and beyond, one click from your repository.
Static code security at a level web development has not seen: end to end, and at a more reasonable price than any competitor. Vauban is built for teams that have to keep their code inside their own infrastructure, or inside the borders of one country. It began because no such platform existed in France, or in Europe more widely, and it now runs the same way for any company, in any country, on infrastructure it owns.
- Far more than SAST: SCA, SBOM, AI Coder and more, one click from your repo
- The same complete offer in the cloud and on your own infrastructure, wherever that infrastructure runs
- Preview environments on Atlas out of the box: analyses run isolated, code is never stored
- Status
- Release Candidate
- Agents
- 3
- Workflows
- 5
A team that cannot let its code leave its own infrastructure still gets complete application security, with nothing given up for the constraint.
Tzu
Policy, Architecture and Audit
Context, plans and governance evidence, decided before the work and proven after it.
Context super-management that turns company policy and architecture into detailed, checkable plans before delivery begins. It then verifies governance and keeps continuous compliance evidence across code and infrastructure.
- Context super-management: one governed source of plans, standards and decisions
- Governance verification across code and infrastructure, not documents alone
- Continuous compliance evidence, retained as an auditable record
- Status
- Beta
- Agents
- 21
- Workflows
- 34
Every product delivers against a written rule, and the evidence that it did exists without anyone assembling it.
Galileo
Systems and API Health Monitoring
Synthetic checks, web journey monitoring and public status signals.
Information stewardship for systems and APIs: synthetic checks that exercise real endpoints, journey monitoring that follows a user through the whole web path, and public status signals your customers can read. It reports what is actually up, not what a dashboard hopes.
- Synthetic checks against live systems and APIs on a fixed cadence
- Web journey monitoring across the whole user path, not a single endpoint
- Public status pages and signals, published from the same evidence
- Status
- Alpha
- Agents
- 1
- Workflows
- 3
Degradation is seen and stated before customers are the ones reporting it.
Moltke
Scenario Simulation
Token forecasts, TCO ranges and system dynamics models, before you commit.
Scenario simulation for decisions that are expensive to reverse: token consumption forecasts, total cost of ownership ranges, and purpose-built system dynamics models. It answers what a plan will cost and how it will behave before the plan is funded.
- Token consumption forecasts across models, workloads and growth curves
- TCO ranges with the assumptions stated, not a single optimistic number
- System dynamics models built for the specific platform under study
- Status
- Beta
- Agents
- 4
- Workflows
- 0
Architecture and budget decisions are taken against modelled ranges rather than estimates.
Plutus
Legal and Platform Control
Terms, rights, privacy and payments, run as workflows rather than documents.
Headless legal workflows and terms management, with a legal and privacy ontology offered as a service. It holds product and user rights, entitlements and payment-provider-backed platform operations for everything the platform sells or grants.
- Headless legal workflows and versioned terms management
- Legal and privacy ontology as a service, queried by the other products
- Product and user rights, entitlements and payment-provider-backed operations
- Status
- Alpha
- Agents
- 25
- Workflows
- 2
What a user has agreed to, is entitled to and has paid for is one governed answer, not three systems.
Leonardo
Deterministic DevSecOps Workflow
Deterministic delivery over governed tools, models and CLI workflows.
Delivery that produces the same result from the same inputs, run over an approved set of tools, models and command-line workflows. It is for teams who need AI inside the pipeline without losing reproducibility or control of what actually ran.
- Deterministic pipelines: the same inputs produce the same artefacts, every run
- Governed access to tools and models, with the chosen versions pinned
- CLI workflows that execute in Atlas microVMs rather than on a developer machine
- Status
- Alpha
- Agents
- 1
- Workflows
- 1
AI-assisted delivery becomes reproducible engineering, auditable step by step.
Nassau
Workstation Security
Developer workstation protection against supply-chain compromise and hostile traffic.
Protection for the machine where code is actually written: supply-chain compromise, malware bridges and hostile traffic behaviour caught at the workstation. It makes the first link in the delivery chain trustworthy before anything reaches the platform.
- Supply-chain compromise detection on dependencies pulled to the workstation
- Malware bridge and hostile traffic behaviour monitoring on the developer machine
- Trusted code, configuration and execution context handed on to the platform
- Status
- Beta
- Agents
- 8
- Workflows
- 2
The delivery chain starts from a workstation proven clean, not assumed clean.
Solon
Telemetry and Costs
Analytics, observability and cost measurement, taken after execution.
Analytics, observability and detailed usage reporting for everything the platform runs, with cost measured from the same records. It turns platform behaviour into operational proof rather than opinion.
- Usage analytics and observability across products, agents and workflows
- Detailed reporting attributed to team, workload and environment
- Cost measured from executed work, and checked against Moltke's forecasts
- Status
- Alpha
- Agents
- 14
- Workflows
- 2
Spend and behaviour are stated as measured fact, ready for an operational or financial review.
Richelieu
Application Foundry
Applications made, released and kept alive on one governed platform.
Richelieu makes applications. It manages their whole life: environments, deployments, artefacts and the DevSecOps lifecycle itself. The work underneath belongs to the other products, but a team never has to assemble them. Richelieu holds the state of every application, decides the order of the work, and calls each product at the point where its work belongs.
- Environments and promotion: dev, test and production run as one path, with every deployment and artefact recorded as evidence
- Each stage executed by the product that owns it: plans, specifications and policy in Tzu, implementation in Leonardo, post-deployment monitoring in Galileo, users, payments and legal in Plutus
- Existing applications imported with the pipelines they already use, then maintained through Leonardo and Tzu rather than rebuilt
- Status
- Alpha
- Agents
- 28
- Workflows
- 19
A team owns the whole life of its applications, from environments and releases to artefacts and maintenance, without assembling that discipline out of separate tools.