Managed cloud
Your tailored system running in an NW Agentic-managed boundary.
- Tailored system compiled for your operation
- No GCP for you to administer
- Operate and govern it from the Cruuvo workspace
- Per-firm budget caps and audit log
Show Cruuvo the outcome, environment, examples, rules, and human decisions. It turns that knowledge into a dependable system your team can run, measure, and improve.
Core, Forge, and Edge are placement profiles—not tiers. Every system is tailored and protected by the same policy, identity, approval, budget, evaluation, and evidence model.
Your tailored system running in an NW Agentic-managed boundary.
Coordinate one system across managed and private boundaries.
For workflows where customer data never leaves the premises.
A trigger arrives. The platform queues the job, evaluates a budget preflight, runs each step with audit before-and-after, optionally pauses for human review, and returns a result. Every transition is observable and reversible.
Each workflow is a stable identity with versioned releases. The control plane catalogs them; you assign a release to a node and enable it independently. There's no "redeploy" to ship a workflow.
Every workflow has a stable workflow_id and a manifest describing triggers, secrets, and risk level.
Each version is a published release with a digest and source commit. Drafts are promoted to approved before assignment.
An approved release is assigned to a specific node, default-disabled. Different nodes can run different versions of the same workflow.
Flip the switch when you're ready. Reversible — disable any time without redeploying anything.
Every guardrail below ships on by default. You opt out per workflow if a use case warrants it, but silent overspend or unlogged steps are not a configurable state.
A monthly token ceiling per firm. A per-job ceiling per workflow. Both raise an error before the API call — not an after-the-fact bill shock.
STARTED and COMPLETED/FAILED for every workflow step. Every LLM call captured with firm, agent, model, tokens, and timestamp.
Retrieval-augmented generation runs against your data. Only the relevant chunks reach the LLM — full documents never leave the node on Private Edge.
Every node carries an MDM-issued device certificate. The control plane authenticates each connection. No shared API keys, no inbound ports.
The split is the same shape across placements, but the surface area you own narrows as the data sensitivity rises.
| Responsibility | Core | Forge | Private Edge |
|---|---|---|---|
| Cloud infrastructure | NWA | NWA | NWA (control plane) |
| On-prem hardware | — | — | NWA (managed appliance) |
| Workflow design | NWA (tailored) | NWA (tailored) | NWA (tailored) |
| Data residency | NWA cloud | NWA cloud and/or customer premises | Customer premises |
| Operator surface | Cruuvo workspace (NWA-hosted) | Cruuvo workspace (NWA-hosted) | Local + control plane (NWA-hosted) |
| Cost controls | Per-firm cap, NWA-enforced | Per-firm cap, NWA-enforced | Per-firm cap, NWA-enforced |
| Human review configuration | You | You + NWA | You + NWA |
| Customer support | NWA | NWA | NWA |
Free 30-minute call. We'll walk through your highest-leverage workflow and recommend a execution placement.
Talk with engineering