Terra · On-premise·Distribution v2026.1 · BSI-certifiable

Your AI. Your ground.

Agenivo Terra runs in the data centre you operate. Full distribution, your models, not a single packet leaves your network – if you do not want it to. Built for banks, insurers, utilities and authorities who must keep every answer on site.

Air-gap
capable under BSI baseline
0 packets
leave your network
Your LLMs
open source of your choice
Overview & features

Sovereign AI platform – feature by feature

Everything Terra does inside your data centre, grouped into five areas. Pick an area and see how the individual building blocks fit together.

  • Terra is not a cloud wrapper but the complete platform – from hardware abstraction to agent logic – shipped as a signed OCI artefact for your Kubernetes cluster.

Agenivo Terra Console
Sovereign AI in your own data centre
  • Your hardwareGPU / CPU · in-DC
  • Terra distributionsigned OCI artefact
  • Local inferencevLLM · BYOM
  • Sealed perimeterWORM audit · 0 egress
Platform stack

Five layers. One distribution. Zero cloud dependency.

Terra is not a wrapper around someone else's cloud. It is the full platform – from hardware abstraction to agent logic – delivered as a signed distribution for your Kubernetes cluster. Every layer is replaceable, every layer is auditable.

05

Agent layer

Skills, tools, conversation

The layer your users talk to. Skill-based agents, tool-calling into your internal APIs, multi-channel routing (widget, WhatsApp, Teams). Configurable from the Terra console, no coding.

Skill studioTool catalogChannel bridgeConversation memory
180+pre-built skills

Distribution ships as a signed OCI artefact. SBOM (CycloneDX) and vulnerability scan report per release.

Three deployment modes

Connected, restricted, air-gapped – you define the perimeter.

Terra is not just "on-premise" as a marketing label. You pick the isolation level and see immediately which paths stay open and which get sealed. Switch between modes any time – the distribution stays identical.

Perimeter profile

Restricted perimeter

Egress only through an approved forward proxy. Updates land in your IT staging bucket first, get reviewed, then released. Default setting for regulated industries.

Best for
  • Banks & insurers
  • Energy & utilities
  • BSI baseline "high"

Updates are signed-verified in your staging registry first. No direct internet visibility from the cluster.

Mode 02
data-centre · your premisesfwd-proxy
Agents · Skillsin-DC
Inference · LLM Runtimein-DC
Platform · Kubernetesin-DC
Egressproxy
Ingressgated
Updates

Forward proxy · IT approval per release

internet · controlled
Bring your own model

You pick the model. We deliver the platform around it.

Terra is model-agnostic. Load your own model into the registry, pick from a pre-validated open-source family or combine several. No licence surprises, no US sub-processors, no token telemetry leak.

Modell-Katalog · live
8vorvalidierte Modelle

+ unbegrenzt eigene Modelle in Ihrer OCI-Registry. Signatur und Lizenz werden beim Deploy geprüft.

EU/DEEU pick

Teuken-7B

OpenGPT-X · Fraunhofer

7 B
Parameter
Empfohlen für

GDPR-critical conversation, German agencies

Lizenz
Apache 2.0
Kontext
4 k
Min.1× L40S (48 GB)
Deployment anfragen
General

Mistral Large 2

Mistral AI · Paris

123 B
Parameter
Empfohlen für

Complex agents, tool calling, multi-step workflows

Lizenz
MRL (commercial)
Kontext
128 k
Min.4× H100 (80 GB)
Deployment anfragen
General

Llama 3.3 70B

Meta · open weights

70 B
Parameter
Empfohlen für

Standard conversation, RAG, classification

Lizenz
Llama 3 Community
Kontext
128 k
Min.2× H100 or 4× L40S
Deployment anfragen
General

Qwen 2.5 72B

Alibaba · open weights

72 B
Parameter
Empfohlen für

Code-adjacent workflows, JSON generation

Lizenz
Qwen License
Kontext
128 k
Min.2× H100 or 4× L40S
Deployment anfragen
Reasoning

DeepSeek R1 distill

DeepSeek · distill 70B

70 B
Parameter
Empfohlen für

Logica hybrid, tax/legal, multi-step reasoning

Lizenz
MIT
Kontext
128 k
Min.2× H100
Deployment anfragen
General

Mixtral 8×22B

Mistral AI

141 B (MoE)
Parameter
Empfohlen für

High throughput on limited GPU

Lizenz
Apache 2.0
Kontext
64 k
Min.2× H100
Deployment anfragen
Embedding

Nomic Embed v2

Nomic · open source

305 M
Parameter
Empfohlen für

RAG indexing, knowledge search

Lizenz
Apache 2.0
Kontext
8 k
Min.CPU or 1× T4
Deployment anfragen
Embedding

BGE-M3

BAAI · open source

567 M
Parameter
Empfohlen für

Hybrid retrieval, multilingual search

Lizenz
MIT
Kontext
8 k
Min.CPU or 1× T4
Deployment anfragen

Model library refreshed quarterly. Your fine-tunes can be loaded into your registry – Terra verifies signature and licence at deploy.

Certification stack

Audit-ready on day one. Actually audited for two years.

Terra is not "compliance-ready" as a promise. The platform is mapped against the controls of the standards below – with evidence artefacts your auditor can drop straight into the report.

Contractually committedIndustry standardOn request
Contractually committed

BSI C5

Cloud Computing Compliance Controls Catalogue

Full mapping against the BSI C5:2020 control catalogue. Type-2 attestation by a Big-Four auditor available.

Status
Attestation 2026 · Type 2
EvidenceAttestation PDF + control mapping
Contractually committed

BSI IT-Grundschutz

High protection demand · modules SYS, NET, APP

Implementation notes for relevant modules of the BSI IT-Grundschutz compendia 2024. Suitable for protection demand "high" and "very high".

Status
Modules covered
EvidenceMeasures table per module
Contractually committed

ISO/IEC 27001

Information security management

ISMS under ISO 27001:2022 incl. ISO 27017 (cloud) and ISO 27018 (personal data). Recertification yearly.

Status
Certified 2025
EvidenceCertificate + statement of applicability
Industry standard

NIS-2

Network and Information Security Directive

Coverage for "essential entities" under § 30 BSIG (NIS-2 transposition act, DE).

Status
Conformity confirmed
EvidenceConformity declaration + risk mapping
Industry standard

KRITIS · § 8a BSIG

Critical infrastructure

State of the art under § 8a BSIG. Terra can be part of your KRITIS evidence; formal proof is issued by your auditor.

Status
Suitable · § 8a evidence possible
EvidenceState-of-the-art report
Contractually committed

EU AI Act

High-risk AI · Annex III

Model cards, risk classification, logging duties and transparency under the EU AI Act (in force 2026) built in by default.

Status
Annex III ready
EvidenceModel card + risk report
Industry standard

TISAX

Automotive information security

Mapping against VDA-ISA. For automotive OEMs and tier-1 suppliers that must evidence TISAX AL 3.

Status
AL 3 possible
EvidenceVDA-ISA mapping
On request

VS-NfD

Classified – for official use only

In air-gapped topology suitable for VS-NfD processing. Higher classification levels on individual review.

Status
Air-gapped variant
EvidenceBSI approval advisory
Audit-Kadenz · External audit yearly · pen-test biannually · internal review quarterly
Lifecycle & operations

Operations that do not look like cloud – they look like your IT.

Terra fits into your existing IT landscape instead of being a second shadow IT. Updates through your registry, monitoring on your Grafana, keys in your HSM. We deliver the platform and the engineering backup – you operate.

< 1 h
P1 response time
monthly
Patch cadence
24/7 · DACH
Engineering backup

Update pipeline

Signed containers, SBOM per release, GitOps rollback in 30 seconds. Air-gap variant ships as an encrypted USB bundle quarterly.

Local observability

Prometheus, Loki and Tempo run in your cluster. No metrics leave the network, Grafana dashboards ship with the distribution.

Identity bridge

Connects to Active Directory, Entra ID, Keycloak or your existing SAML/OIDC provider. Roles sync via group mapping.

WORM audit store

Every answer, every tool call, every model decision in a write-once-read-many layer. Verifiable for 10 years.

Bring your own key

HSM integration (Thales Luna, Utimaco, on-prem CloudHSM) for master keys. We never see your data in plaintext, even if we wanted to.

Capacity planning

Sizing tool with real workload profiles for your use cases. No "just buy two H100 to be safe" – concrete hardware proposals with ROI.

Engineering backup

Named account engineer in DACH timezone. P1 response under one hour, P2 within four hours – even in air-gap setups over the agreed channel.

Vulnerability management

CVE scan in every release pipeline. CVSS-7+ findings addressed before shipping, emergency patches within 72 hours.

Onboarding & migration

Guided go-live on a validated reference architecture. Existing knowledge base, prompts and skills are migrated – pilot in weeks, not quarters.

Backup & recovery

Consistent snapshots of models, index and configuration. Defined RPO/RTO, restore inside your own data centre – without any external copy.

Q&A · On-Prem-Ebene01 → 08
  • In air-gap mode the cluster has no outbound network path to the internet – not directly, not via proxy. No telemetry, no automated update calls, no external DNS. Updates ship quarterly as a signed bundle (Sigstore chain) on physical media through your security airlock. We test this topology regularly with customers in KRITIS core zones and authorities handling classified data.

Next step

Architecture call · 60 minutes · your topology on the table

We sit down with your architects and CISO, walk through network topology, compliance demands and target models. By the end of the call you will know whether Terra fits your landscape – and which mode (connected, restricted, air-gapped) is the right one.

The call is run by our platform engineering team, not a sales funnel. NDA signed upfront if you prefer.