Terra · On-premise·Distribution v2026.1 · BSI-certifiable

Your AI. Your ground.

Agenivo Terra runs in the data centre you operate. Full distribution, your models, not a single packet leaves your network – if you do not want it to. Built for banks, insurers, utilities and authorities who must keep every answer on site.

Air-gap
capable under BSI baseline
0 packets
leave your network
Your LLMs
open source of your choice
Platform stack

Five layers. One distribution. Zero cloud dependency.

Terra is not a wrapper around someone else's cloud. It is the full platform – from hardware abstraction to agent logic – delivered as a signed distribution for your Kubernetes cluster. Every layer is replaceable, every layer is auditable.

Earth-layer diagram
Surface · end users
Bedrock · your hardware
05
Skin

Agent layer

Skills, tools, conversation

The layer your users talk to. Skill-based agents, tool-calling into your internal APIs, multi-channel routing (widget, WhatsApp, Teams). Configurable from the Terra console, no coding.

Skill studioTool catalogChannel bridgeConversation memory
pre-built skills
180+
Layer 05 / 05

Distribution ships as a signed OCI artefact. SBOM (CycloneDX) and vulnerability scan report per release.

Three deployment modes

Connected, restricted, air-gapped – you define the perimeter.

Terra is not just "on-premise" as a marketing label. You pick the isolation level and see immediately which paths stay open and which get sealed. Switch between modes any time – the distribution stays identical.

Perimeter profile

Restricted perimeter

Egress only through an approved forward proxy. Updates land in your IT staging bucket first, get reviewed, then released. Default setting for regulated industries.

Best for
  • Banks & insurers
  • Energy & utilities
  • BSI baseline "high"

Updates are signed-verified in your staging registry first. No direct internet visibility from the cluster.

Mode 02
data-centre · your premisesfwd-proxy
Agents · Skillsin-DC
Inference · LLM Runtimein-DC
Platform · Kubernetesin-DC
Egressproxy
Ingressgated
Updates

Forward proxy · IT approval per release

internet · controlled
Bring your own model

You pick the model. We deliver the platform around it.

Terra is model-agnostic. Load your own model into the registry, pick from a pre-validated open-source family or combine several. No licence surprises, no US sub-processors, no token telemetry leak.

Modell-Katalog · live
8vorvalidierte Modelle

+ unbegrenzt eigene Modelle in Ihrer OCI-Registry. Signatur und Lizenz werden beim Deploy geprüft.

EU/DEEU pick

Teuken-7B

OpenGPT-X · Fraunhofer

7 Bparams

EU-trained · 24 languages · clean dataset

Lizenz
Apache 2.0
Kontext
4 k
Empfohlen für
GDPR-critical conversation, German agencies
1× L40S (48 GB)
General

Mistral Large 2

Mistral AI · Paris

123 Bparams

Best EU alternative · function calling · multilingual

Lizenz
MRL (commercial)
Kontext
128 k
Empfohlen für
Complex agents, tool calling, multi-step workflows
4× H100 (80 GB)
General

Llama 3.3 70B

Meta · open weights

70 Bparams

Best price/perf · broad tool support

Lizenz
Llama 3 Community
Kontext
128 k
Empfohlen für
Standard conversation, RAG, classification
2× H100 or 4× L40S
General

Qwen 2.5 72B

Alibaba · open weights

72 Bparams

Strong on structured outputs · 29 languages

Lizenz
Qwen License
Kontext
128 k
Empfohlen für
Code-adjacent workflows, JSON generation
2× H100 or 4× L40S
Reasoning

DeepSeek R1 distill

DeepSeek · distill 70B

70 Bparams

Reasoning chain on-prem · distilled from R1

Lizenz
MIT
Kontext
128 k
Empfohlen für
Logica hybrid, tax/legal, multi-step reasoning
2× H100
General

Mixtral 8×22B

Mistral AI

141 B (MoE)params

MoE efficiency · only 39 B active per token

Lizenz
Apache 2.0
Kontext
64 k
Empfohlen für
High throughput on limited GPU
2× H100
Embedding

Nomic Embed v2

Nomic · open source

305 Mparams

MTEB-leading · 100+ languages · CPU-capable

Lizenz
Apache 2.0
Kontext
8 k
Empfohlen für
RAG indexing, knowledge search
CPU or 1× T4
Embedding

BGE-M3

BAAI · open source

567 Mparams

Dense + sparse + multi-vector in one model

Lizenz
MIT
Kontext
8 k
Empfohlen für
Hybrid retrieval, multilingual search
CPU or 1× T4

Model library refreshed quarterly. Your fine-tunes can be loaded into your registry – Terra verifies signature and licence at deploy.

Certification stack

Audit-ready on day one. Actually audited for two years.

Terra is not "compliance-ready" as a promise. The platform is mapped against the controls of the standards below – with evidence artefacts your auditor can drop straight into the report.

Contractually committedIndustry standardOn request
Contractually committed

BSI C5

Cloud Computing Compliance Controls Catalogue

Full mapping against the BSI C5:2020 control catalogue. Type-2 attestation by a Big-Four auditor available.

Status
Attestation 2026 · Type 2
Attestation PDF + control mapping
Contractually committed

BSI IT-Grundschutz

High protection demand · modules SYS, NET, APP

Implementation notes for relevant modules of the BSI IT-Grundschutz compendia 2024. Suitable for protection demand "high" and "very high".

Status
Modules covered
Measures table per module
Contractually committed

ISO/IEC 27001

Information security management

ISMS under ISO 27001:2022 incl. ISO 27017 (cloud) and ISO 27018 (personal data). Recertification yearly.

Status
Certified 2025
Certificate + statement of applicability
Industry standard

NIS-2

Network and Information Security Directive

Coverage for "essential entities" under § 30 BSIG (NIS-2 transposition act, DE).

Status
Conformity confirmed
Conformity declaration + risk mapping
Industry standard

KRITIS · § 8a BSIG

Critical infrastructure

State of the art under § 8a BSIG. Terra can be part of your KRITIS evidence; formal proof is issued by your auditor.

Status
Suitable · § 8a evidence possible
State-of-the-art report
Contractually committed

EU AI Act

High-risk AI · Annex III

Model cards, risk classification, logging duties and transparency under the EU AI Act (in force 2026) built in by default.

Status
Annex III ready
Model card + risk report
Industry standard

TISAX

Automotive information security

Mapping against VDA-ISA. For automotive OEMs and tier-1 suppliers that must evidence TISAX AL 3.

Status
AL 3 possible
VDA-ISA mapping
On request

VS-NfD

Classified – for official use only

In air-gapped topology suitable for VS-NfD processing. Higher classification levels on individual review.

Status
Air-gapped variant
BSI approval advisory
Audit-Kadenz · External audit yearly · pen-test biannually · internal review quarterly
Lifecycle & operations

Operations that do not look like cloud – they look like your IT.

Terra fits into your existing IT landscape instead of being a second shadow IT. Updates through your registry, monitoring on your Grafana, keys in your HSM. We deliver the platform and the engineering backup – you operate.

< 1 h
P1 response time
monthly
Patch cadence
24/7 · DACH
Engineering backup

Update pipeline

Signed containers, SBOM per release, GitOps rollback in 30 seconds. Air-gap variant ships as an encrypted USB bundle quarterly.

Cosign + Sigstore · CycloneDX SBOM · ArgoCD compatible

Local observability

Prometheus, Loki and Tempo run in your cluster. No metrics leave the network, Grafana dashboards ship with the distribution.

OpenTelemetry · 30+ dashboards · optional PagerDuty bridge

Identity bridge

Connects to Active Directory, Entra ID, Keycloak or your existing SAML/OIDC provider. Roles sync via group mapping.

SCIM 2.0 · SAML 2.0 · OIDC · just-in-time provisioning

WORM audit store

Every answer, every tool call, every model decision in a write-once-read-many layer. Verifiable for 10 years.

S3 Object Lock compatible · MinIO or NetApp · sha256 chain

Bring your own key

HSM integration (Thales Luna, Utimaco, on-prem CloudHSM) for master keys. We never see your data in plaintext, even if we wanted to.

PKCS#11 · KMIP · automatic rotation

Capacity planning

Sizing tool with real workload profiles for your use cases. No "just buy two H100 to be safe" – concrete hardware proposals with ROI.

Excel sizing · reference designs · stretch tests in lab

Engineering backup

Named account engineer in DACH timezone. P1 response under one hour, P2 within four hours – even in air-gap setups over the agreed channel.

24/7 · escalation path to CTO · DACH staff

Vulnerability management

CVE scan in every release pipeline. CVSS-7+ findings addressed before shipping, emergency patches within 72 hours.

Trivy + Grype · CVE feed · notification webhook

Q&A · On-Prem-Ebene01 → 08
  • In air-gap mode the cluster has no outbound network path to the internet – not directly, not via proxy. No telemetry, no automated update calls, no external DNS. Updates ship quarterly as a signed bundle (Sigstore chain) on physical media through your security airlock. We test this topology regularly with customers in KRITIS core zones and authorities handling classified data.

Next step

Architecture call · 60 minutes · your topology on the table

We sit down with your architects and CISO, walk through network topology, compliance demands and target models. By the end of the call you will know whether Terra fits your landscape – and which mode (connected, restricted, air-gapped) is the right one.

The call is run by our platform engineering team, not a sales funnel. NDA signed upfront if you prefer.