The runtime deploys inside the customer's own account, so evidence and keys never leave their boundary.
No customer deployment has been performed.
EcoKure is one assurance runtime with one evidence contract. Where it runs is a deployment decision, not a different product. Evidence, signing keys and decision records stay inside the environment you control, which is also the answer to the supplier-concentration and exit questions a regulated buyer has to satisfy.
Listed with a validation state rather than as five equivalent options. Most vendors would show six logos here. Four of these are not built, and saying so is worth more than the logos.
The runtime deploys inside the customer's own account, so evidence and keys never leave their boundary.
No customer deployment has been performed.
A reference environment defined entirely in Terraform and applied: VPC with public and private subnets, EC2 with IMDSv2 required, RDS PostgreSQL, an asymmetric KMS signing key, Secrets Manager for the database credential, CloudWatch, and a least-privilege instance role with no access key anywhere.
Target-environment evidence is recorded; this is not production customer validation, certification or a Well-Architected review.
Target: AKS with Entra ID, Key Vault and Azure Database for PostgreSQL, sharing the same evidence semantics.
No Azure packaging exists.
Target: GKE or customer infrastructure with Cloud KMS and Cloud SQL, sharing the same evidence semantics.
No GCP packaging exists.
Container or Kubernetes package against a customer's own PostgreSQL and key service.
Not packaged or tested as a supported deployment.
Disconnected operation with local signing and offline replay. A differentiator for sovereignty, not a fallback.
No air-gapped deployment has been built or accredited.
The interactive walkthrough shows the operating model with illustrative records. The AWS reference architecture below is the next environment to validate that same control, signing and evidence path. These are deliberately shown as two linked stages, not as two different products.
Read-only product flow covering decision stream, human review, change impact and evidence.
Illustrative data only. No customer data or external service calls.
Open the demo →Customer-boundary reference architecture for the same evidence contract and replay semantics.
The environment is not presented as production-ready until benchmark, security and operational validation are complete.
See the reference path →Written as Terraform and applied. This is the environment a Solutions Architect or a customer’s cloud team would review — every component with the reason it is there, because an architecture list without reasons is a parts bin.
Measured run 2026-08-27 · ap-southeast-2 · TARGETREP_AWS_20260827
The same assurance path has now been exercised on the AWS reference environment: signed verification, PostgreSQL persistence, controlled recovery and clean teardown.
KMS: ECC_NIST_P256 with independent public-key verification · Store: RDS PostgreSQL · Loss: 0
Open machine-readable result →Boundary: Target-environment evidence, not production customer validation, certification, or a Well-Architected review. Cost signal: US$0.00001515 per modeled assurance transaction, not a production quote.
The AWS run closes the measurement gap. These are the next gates for a customer-controlled production reference, kept visible so a benchmark is not mistaken for operational readiness.
Resilience and recovery
Move from single-AZ reference evidence to customer-approved multi-AZ design, backup/restore objectives and repeated recovery drills.
Operational ownership
Define staging, on-call ownership, alert thresholds, incident response, change approval and release rollback.
Security assurance
Complete threat modelling, dependency/SBOM review, penetration testing and customer IAM/network review.
Customer validation
Run one bounded pilot in the customer boundary, with their controls, data boundary, reviewers and written go/no-go criteria.
Only the infrastructure boundary changes. The assurance semantics — the verdict contract, the signed chain, replay — are identical everywhere, or portability is not real.
| Portable layer | AWS | Microsoft Azure | Google Cloud | Customer / offline |
|---|---|---|---|---|
| Runtime artifact | OCI container on EC2, ECS or EKS | AKS or Container Apps | GKE or customer infrastructure | Docker or Kubernetes, disconnected |
| Transactional store | RDS PostgreSQL | Azure Database for PostgreSQL | Cloud SQL for PostgreSQL | Customer PostgreSQL |
| Signing key | KMS asymmetric, or CloudHSM | Key Vault or Managed HSM | Cloud KMS or Cloud HSM | PKCS#11 / local HSM |
| Evidence objects | S3 | Blob Storage | Cloud Storage | Customer object store |
| Identity | IAM + enterprise OIDC | Entra ID | Cloud Identity / OIDC | Customer directory |
| Observability | CloudWatch + OpenTelemetry | Azure Monitor + OpenTelemetry | Cloud Monitoring + OpenTelemetry | Customer SIEM |
| Evidence semantics | Identical. Same signed decision record, same chain construction, same replay. This row is the product. | |||
Answered here rather than in a meeting, including the answers that are “not yet”.
What is the workload shape?
Short, CPU-bound deterministic checks plus a signing operation and an append to a transactional store. No GPU. No model inference. The runtime carries 11 dependencies.
Where does customer data live?
Inside the customer’s account. The evidence store holds an input digest, not the input, so customer content does not enter it at all.
How is tenancy separated?
Tenant identity is resolved from the authenticated credential and never from a request field. Evidence attribution lives in a private index rather than on the published chain. Tested adversarially.
What is the failure mode?
Fail-closed by default: if the evidence store is unavailable, a strict deployment refuses rather than returning a verdict that looks attested and is not.
What does it cost per transaction?
Measured as a target-environment signal. The recorded modeled cost is US$0.00001515 per assurance transaction, excluding tax, support plans, free-tier credits, reserved pricing and shared-account costs. It is not a production price or customer quote.
Is it production-ready on AWS?
Not yet. The target-representative benchmark has passed, but this does not establish production customer validation, a Well-Architected review, a Foundational Technical Review or a marketplace listing.
Three properties. Two hold today and are checkable; the third is the one that needs a real deployment to prove.