Self-SaaS

Your cloud. Your data. Your call. That's Self-SaaS.

Every log, metric, trace, profile, RUM session and LLM event stays inside your VPC, under your own keys. How much Kloudfuse manages the platform is yours to decide.

SaaS simplicity. Full control. Without the trade.

For a decade observability gave you two options. Hand your production telemetry to a vendor, or hire a team to run the platform yourself.

Self-SaaS is our name for the third option, and it is already running in production inside healthcare, financial services and regulated government environments.

Pay for the platform, not the volume

Predictable pricing on infrastructure you already run. The bill does not scale with hosts, metrics, log lines or how many engineers you hired this quarter.

Your data, your keys, your boundary

Telemetry stays in your VPC. Customer-managed encryption keys across AWS, Azure and GCP, with access controls at org, team and per-user level.

Engineered for the AI era, not retrofitted

LLM observability, an MCP server and an AI SRE that investigates and drafts. All inside your VPC, on your telemetry, with your engineers deciding what happens next.


One platform in your cloud. One thin line out of it.

The entire data path runs inside your environment: ingest, storage, query and the AI layer. For managed deployments, Kloudfuse operates the lifecycle from the outside, over a channel that carries version state and health signals and nothing else.

Kloudfuse Self-SaaS deployment architectureThe Kloudfuse platform runs entirely inside your VPC: sources feed ingest and normalisation, a unified data lake, a query engine and an AI runtime, all writing to your own storage.KLOUDFUSE SELF-SAAS ARCHITECTUREYOUR VPC · SELF-SAASSOURCESOpenTelemetry-compatible agentOSS agentsPrometheus · Fluent BitCommercial agentsDatadog · SumoLogicNew Relic · ElasticCloud servicesaws · azure · gcpIngest andnormalizeschema · enrichrelabelQuery enginePromQL · LogQL · TraceQLFuseQL · GraphQL APIUnified data lakelogs · metrics · tracesevents · RUM · profilesLLM telemetryGoverned accessRBAC gate · policiesauditYour storageyour bucketyour retentionGenerated RCAdraft reportproposed fixesAI runtimeruns on your own model,in your VPCLocal modelsMCP serverAgentsDexterAI SREdrafts, you decideHuman SREapproves beforeanything shipsGOVERNANCEcustomer-managed keys · RBAC org / team / per-user · SSO · audit logsretention policies

A category, not a deployment toggle.

BYOC is the term the market uses for running the data plane in your own cloud. Self-SaaS is how we describe what is different about ours: the complete data path, including the query engine and AI layer, runs inside your VPC, with operational models from self-operated to fully managed by Kloudfuse.

  SaaS observability Self-managed open source Self-SaaS
Where telemetry lives The vendor's cloud Your cloud, your stack Your VPC, under your keys
Operational burden Low High, and it needs a dedicated team Your choice, from self-operated to fully managed
Cost model Per host, per metric, per log line, per seat Infrastructure plus headcount Predictable
Governance and RBAC Defined by the vendor Build it yourself Stream-level, team-level, per-user
AI access to telemetry Sent to the vendor Build it yourself Stays in your VPC, on your own model
Upgrade model Forced, on the vendor's schedule Yours to plan and run Self-operated: yours to plan; managed: you approve the window, we run it
Encryption keys Held by the vendor Self-managed Customer-managed, BYOK and CMK
Audit posture The vendor's scope Your scope, your tooling Your scope, exportable to your SIEM
Custom-metric tax Per-metric surcharge None, but you carry the cardinality yourself None, every dimension stored rather than sampled
Dedicated tenancy A premium add-on By definition Included by architecture

Already running. Inside the strictest boundaries.

Three industries, three different reasons for needing the data to stay put, one architecture underneath.

Observability inside its own security boundary

  • 300+ TB of telemetry a day, and growing
  • 78 engineering teams on one queryable lake
  • More than 30 tools consolidated into one
  • Sensitive telemetry never leaves the boundary

From vendor lock-in to open standards

  • Consolidated off legacy SaaS observability
  • Flat, predictable cost on their own infrastructure
  • 86% reduction in mean time to resolution
  • High-cardinality metrics kept without a premium tier

Unified observability for healthcare engineering

  • Hundreds of users across engineering, DevOps, QA and support
  • 23% reduction in mean time to resolution
  • 50% fewer customer-reported incidents
  • Data residency preserved inside the customer VPC
Read customer stories


What architects ask before they sign off.

Is Self-SaaS the same as BYOC?

BYOC means the data plane runs in your cloud, and Kloudfuse qualifies. Self-SaaS is how we describe what makes ours different: the complete data path, including the query engine and AI layer, runs inside your VPC. And unlike most BYOC implementations, you choose how much Kloudfuse manages, from self-operated to fully managed in your cloud.

What are my options for how Kloudfuse is operated?

Three. Self-operated: your team deploys and runs the platform, we provide the software and support. Co-managed: your cluster, our team handles upgrades and lifecycle management. Fully managed: we run the complete service inside your VPC, for teams who want SaaS convenience without SaaS data exposure.

Do I need a platform team to run Kloudfuse?

It depends on how you want to engage. Self-operated customers run the platform themselves, no different from running any Kubernetes-based workload. For teams who want less overhead, we offer co-managed and fully managed options. Either way, your data never leaves your VPC.

Where does my telemetry live?

Inside your VPC, in your cloud account, under your keys. Production telemetry never moves into a Kloudfuse-owned cloud.

What does the control plane do?

Operational metadata over a secure channel: version state, upgrade status, health signals and entitlement. Logs, metrics, traces, events, RUM, profiles and LLM telemetry stay in the data plane.

Does the AI run in my environment too?

Yes. The MCP server, LLM observability and Dexter all run inside the data plane, on a model in your own VPC. Connect an external provider only if you choose to. Dexter investigates and proposes; it does not execute changes.

Can I pass SOC 2, ISO 27001 or HIPAA reviews?

Kloudfuse supports SOC 2 Type II and FIPS 140-3 validated cryptography, and customers in healthcare, fintech and other regulated sectors run it in audit-bound environments. For FedRAMP, talk to our team.

How do upgrades work?

For managed deployments, through the control plane on a scheduled or on-request basis: you approve the window, we run it. For self-operated deployments, your team manages the upgrade cycle using standard tooling.

How is this different from self-hosted observability?

Self-hosted typically means you assembled it from open source and you run it. Self-SaaS means the platform is production-ready and enterprise-grade, deployed in your cloud. How much Kloudfuse is involved in operations is your choice, from self-operated to fully managed.

How is this different from a private SaaS or a dedicated tenant?

A private SaaS still runs in the vendor's cloud, however dedicated the tenancy. Self-SaaS runs the data plane in your cloud, under your accounts and your keys.

Can I deploy on-prem or across more than one cloud?

Yes. AWS, Azure, GCP and selected private or on-prem environments.

Bring an incident. We'll bring the platform.

Thirty minutes on your telemetry. The cause, before the call ends.