VorsalOS
HomePlatformArchitecture
ARCHITECTURE

The mental model, layer by layer.

Five layers, each access-controlled, auditable, and deployed inside your boundary. Start at the secure foundation and build up to the workflows your teams run every day.

Click any layer to expand its specifics
Private models in your boundary
VPC, on-prem, sovereign & air-gapped
Bring your own models (model gateway)
Encryption at rest & in transit (CMK)
Network isolation & IP allow-listing
No public-AI exposure
LAYER BY LAYER

What each layer actually does.

05

Workflows

End-to-end business processes

Multi-agent orchestration
Triggers, schedules & events
Human approval gates
Branching & conditional logic
Run history & replay
SLA & ownership per process
04

Agents

Autonomous, supervised execution

Goals, memory & planning
Supervised or fully autonomous
Tool & system access via connectors
Guardrails & policy constraints
Human-in-the-loop checkpoints
Every action audited
03

Skills

Reusable capabilities & marketplace

Defined input → output contract
Versioned & testable
Composable into agents
Private or marketplace-sourced
Permissioned per role
The atomic unit of work
02

Organisational intelligence

Your knowledge, structure & policy

Grounded RAG over your data
Access-controlled retrieval
Org structure, policy & procedure graph
Connectors to your systems of record
Source citations on every answer
No training on your data
01

Secure infrastructure

Private models · VPC · on-prem · sovereign

Private models in your boundary
VPC, on-prem, sovereign & air-gapped
Bring your own models (model gateway)
Encryption at rest & in transit (CMK)
Network isolation & IP allow-listing
No public-AI exposure
HOW A REQUEST FLOWS

Every request is grounded, governed, and cited.

No request reaches a model without passing identity and access control first. Retrieval is grounded in your data, and every answer carries its sources.

01
Request

A user or workflow invokes a skill or agent.

02
Identity & RBAC

SSO identity resolved; role permissions checked.

03
Grounded retrieval

Access-controlled RAG pulls only permitted data.

04
Private inference

The model runs inside your boundary — never public.

05
Cited response

Every claim carries its source references.

06
Audit log

The full path is logged and exportable.

The entire path executes inside your VPC, private cloud, or sovereign region — nothing leaves your boundary.

See the architecture running on your stack.

A 30-minute technical walkthrough — deployment topology, the retrieval path, and the security model — with our engineering team.