FOR OPERATORS

A productized connectivity layer for AI and SaaS operators.

If your platform needs to reach customer data on customer infrastructure, you have three options. Build it yourself. Push the work to your customers via VPN setup guides. Or run Ewii. This page is for operators considering option three.

Cutaway cross-section of the Ewii Hub binary, a stylized tall rectangular vessel with the front face removed. Five stacked internal subsystems are visible: Tenant Registry, Connection Broker, Query Authorization (highlighted), Audit Emitter, and Metrics Plane. Dashed leader lines connect each subsystem to labelled callout blocks in the right margin.
FIG. 1 Hub binary anatomy — five internal subsystems from trust registry to metrics emission.

Hub deployment characteristics

The Hub runs as an OCI container in your infrastructure: your VPC, your Kubernetes cluster, your bare-metal. The control plane is a single binary; a connection-handling relay node accepts up to 10,000 concurrent Client connections by documented default, and a Hub region scales horizontally with N relay nodes behind a Layer-4 load balancer. We provide the binaries, the images signed with Cosign, the deployment manifest, the capacity-planning notes, and the operational runbook. Your team owns the rollout. We back you up.

Multi-tenancy at the Hub level

A single Hub serves many customers concurrently. Tenants are cryptographically isolated: each customer’s SPIFFE trust bundle is independent, and the Hub enforces tenant boundaries at the connection layer before any application traffic flows. There is no shared-key cross-tenant code path. A compromise of one tenant’s Client provides no path to another tenant’s traffic via the cryptographic boundary.

White-label and rebranding options

The Client container can be retagged and branded with your product name. The web experience your customers see when installing the Client — setup instructions, status page, support links — is fully customizable. Your customers see your brand; we sit behind it. Trust attribution stays with us only when a customer asks where the security model comes from, and you point them here.

Operational fit

Prometheus metrics out of the box: connection counts, handshake latency, ChaCha20-Poly1305 throughput, replay-window rejections, certificate-rotation events. Structured logs (JSON) for SIEM ingestion. Indicative SLA targets are 99.95% steady-state availability per Hub region and 99.9% during planned windows; contractual SLAs are negotiated per engagement and depend on your chosen deployment topology and the support tier you select. PagerDuty integration is your call; we don’t ship a paging system.

The Architecture Review process

Every operator engagement starts with a 60-minute Architecture Review. Our senior architect and security lead attend. No account executive, no sales pitch. We walk through your platform’s data flow, your customers’ security posture, and the deployment shape that fits both. You leave with three artifacts: a draft architecture diagram, a security-responsibilities matrix (who owns what), and a deployment plan. Whether you adopt Ewii after that is your call — we don’t bill for the review.

Ready for a 60-minute conversation?

Schedule an Architecture Review