eparch
GitHubGet started

ENTERPRISE

Built for the environments other platforms can't enter.

Regulated industries, sovereign clouds, air-gapped networks. Eparch is designed from the database up for deployments where "just use the API" was never an option.

AIR-GAPPED INSTALL

Zero external egress

Eparch installs from an offline image bundle and runs with no external network access at all. Every dependency — Postgres, Redis, MinIO, OPA, your model server — lives inside your perimeter.

HARD MULTI-TENANCY

Isolation the database enforces

Data-plane services connect as a non-superuser role with Postgres row-level security applied to every query. Tenant isolation is a database guarantee, not an application convention.

POLICY

OPA on every service

An Open Policy Agent interceptor authorizes every request across all ten services. Your security team writes policy once; the platform enforces it everywhere.

AUDIT + COST

An immutable record of everything

Immutable, per-tenant audit logs and usage/cost accounting for every request that touches a model — the evidence trail your auditors ask for, produced by default.

IDENTITY

Enterprise SSO and SCIM

Login brokered to WorkOS AuthKit for SSO, with signature-verified SCIM deprovisioning webhooks — or fully local email/password auth where no external IdP is allowed.

BYO INFERENCE

Your models, your hardware

The gateway speaks the OpenAI-compatible API. Point it at vLLM, Ollama, or any compatible endpoint — open-weight models on GPUs you control, with budgets and routing on top.

TALK TO US

Request a private architecture briefing.

A working session with the people who built Eparch: your environment, your constraints, and an honest read on whether Eparch fits. No slideware, no sales rotation.

You'll hear from a founder within one business day.