
Isolation That Goes All The Way Down
Tenant domains carved into the fabric, not layered on top of it. Policy enforced at the workload flow, in DPU hardware. Lifecycle owned from provisioning to production.
Tenant-scoped VPCs, routing, addressing, and policy provisioned as first-class fabric constructs. Isolation enforced across both the north-south Ethernet path and the east-west GPU-direct RDMA fabric.
Policy at the flow, enforced in silicon
Flow-level policy
Process-to-process reachability by tenant, workload, interface, and service boundary.
Hardware enforcement
DPU-level flow control at the interface.
Per-tenant security domains
Policy, routing, addressing, and enforcement versioned as managed configuration.
Network provisioning
Create private networks, stable IPs, routing, DNS, and VPC peering. IP control with static IPs, BYOIP, or Radiant pools for inference endpoints; tenant-isolated DNS, NTP, and stateful firewall.

Private interconnects
Establish dedicated links between clusters, storage, enterprise networks, and external environments - over private paths, with BGP.

Topology-aware lifecycle
Topology-aware placement
Workloads mapped against physical switch topology to minimize hops and tail latency
Lifecycle ownership
VPCs, routes, policies, interfaces, and service exposure under lifecycle control from bare-metal provisioning through configuration updates
Standards-based routing
Orchestrator logic over proven routing platforms, no software-defined latency penalty
