Factory Private
Enterprise AI
Self-hosted AI agents and control-plane ownership
September 18, 2026 - 2 minute read
Factory Private
Enterprise AI
September 18, 2026 - 2 minute read
Installing a coding agent locally and operating the service behind its sessions are different jobs. The control plane coordinates sessions and supporting services. Self-hosted AI agents can put that service under the customer's control, which also makes its updates, availability, and recovery part of the customer's operating work.
Before choosing customer hosting, identify the team that would restore the control plane after a failed upgrade and the process it would use. An internal model key or a local executable cannot answer that operational question.
Factory offers a managed control plane and a customer-owned alternative. Factory Managed provides hosted orchestration and operations while Droids can run across existing development environments.
Factory Private puts the control plane in customer infrastructure. The published comparison identifies differences in ownership, data boundary, and access controls.
Best for
Teams that want Factory-managed operations and analytics.
Data boundary
Customer content is tenant-isolated within Factory’s managed environment.
Security and access
Enterprise Controls govern models, access, telemetry, and autonomy.
Control plane
Factory-hosted.
Droid execution
Local machines, CI/CD, BYOM, or Factory-managed Droid Computers.
Operations and updates
Factory operates the control plane. Your team operates local and CI environments.
Telemetry and analytics
Factory Analytics or OpenTelemetry export.
Best for
Teams that need Factory in their VPC or on-premises environment.
Data boundary
Customer data remains in your environment.
Security and access
Your IAM, network, and security controls govern the deployment.
Control plane
Customer-hosted.
Droid execution
Local machines, CI/CD, and your BYOM infrastructure.
Operations and updates
Your team operates the deployment and controls updates.
Telemetry and analytics
Factory telemetry and OpenTelemetry export to your collector.
The ownership choice sets the operator's responsibilities. Model routing and execution permissions still need their own configuration, whichever control plane the organization uses.
Bringing an approved model does not move every supporting service into the customer network. Factory's sovereign software development whitepaper distinguishes Managed control-plane and session-data hosting from Private's customer-hosted placement.
Review session handling separately from inference. Record where context is stored, which model service receives requests, and what the gateway logs. Include retries, fallbacks, and support diagnostics in the diagram.
Factory's deployment documentation describes the runtime and traffic differences between cloud-managed, hybrid, and airgapped patterns. Use the intended pattern to test the complete workflow, not just its first successful model response.
Operating a private control plane requires a release and recovery process. For example, rehearse an update in a disposable environment, then restore the previous approved configuration and run a known task. A successful recovery should not depend on undocumented steps in one administrator's shell.
The model service needs an owner too. A new model version can alter task behavior even when the agent build stays fixed. Keep representative validation tasks and review the results before promotion.
Monitor the dependency that can stop work. Adding execution machines will not repair a saturated inference service or an unavailable internal package mirror. Distinguish those failures from agent errors so the response goes to the team that can resolve them.
Support access also belongs in the plan. Agree on which diagnostics may leave the environment, how sensitive content is removed, and who approves release. Avoid making troubleshooting an undocumented exception to the boundary.
Airgapped operation adds a no-runtime-connectivity requirement. Factory's airgap build uses customer-configured models and disables Factory-bound services. Cloud-dependent features such as Slack integration and hosted analytics are unavailable.
Before developers depend on the service, make sure another operator can promote an update, recover a failed one, and collect permitted diagnostics. Those procedures determine whether customer control is usable when the system needs maintenance.
A deployment and governance framework for the world's most important systems, from managed to air-gapped.
Read the white paper
Discuss your team’s software development, privacy, or deployment requirements.
Start building