enterprise: You own the execution layer.

ConvOps is the governance layer for your enterprise AI operations. Teach your process once. Every AI and every person runs it the same way, on your infrastructure.

self-hosted · your Kubernetes · your models

ConvOps cloud6 of 8
Engine
Brain
Audit
Web app
Runs
Secrets
MCP over HTTPSoutbound only
Your Kubernetes2 of 8
Models
Repos

Cloud We run the governance. Your AI tools, models and repositories stay yours and connect over MCP.

in short

What does ConvOps give an enterprise AI program?

The governance layer for enterprise AI operations: one process for every AI tool and team, approvals that hold, an audit trail, and the option to self-host on your Kubernetes.

ConvOps is the operations layer for AI agents: an MCP server that holds your team's process as workflows, with approval gates, a shared memory and an audit trail. It runs no AI models.

key facts · october 2026

  • Self-hosted, the engine, the brain, the audit and every run live in your own Kubernetes cluster, installed from one Helm chart.
  • You bring the model provider and credentials. Runs use Claude Code or OpenCode today.
  • Claude, Cursor, ChatGPT and Codex connect over MCP, so teams keep the AI tools they use.
  • Approval gates and field-level audit rows support the human oversight that Article 14 of the EU AI Act asks for.
  • Enterprise is quoted per organization, from $2,500 a month, under a commercial licence.

best for

  • Companies rolling AI agents out to several teams that need one process and one record.
  • Regulated organizations that cannot send code or data outside their cluster.

not for

  • Buying AI models or seats. ConvOps does not resell models and does not price per seat or per token.

updated

the questions

Where does our code run?

Security asks that first. The business asks the next three, usually after something went wrong.

“Who approved that?”

An agent changed something that matters. The approval lived in a chat, if it happened at all.

“Where did that decision go?”

It was made in one AI tool, in one session, by one person. Nobody else can find it now.

“What happens when someone leaves?”

The process lived in their prompts. It leaves with them, and the AI never learned it.

the architecture

Your stack, governed.

Your AI tools on top. ConvOps in the middle, holding the process. Your executors and your cluster underneath, doing the work.

your AI toolskeep them
Claude
Cursor
ChatGPT
Codex
MCP
ConvOps owns the governancecloud or self-hosted
Workflow enginesteps, in order
Braindecisions, reasons
Governancegates · audit · roles
waiting for workexample
dispatch
you own the execution layer
Your machinelocal
Your runnercustom
Isolated runKubernetes
your Kubernetes · convops-runsone pod per run
free
free
free
free
what you control

Yours, end to end.

The cluster, the models, the keys, the network, the record and the boundaries between teams. ConvOps governs the work; it does not take any of these.

Your cluster

Every run is a pod in your Kubernetes. Self-hosted, the engine, the brain and the audit live there too.

one Helm chart

Your models and keys

Bring your own model provider and credentials. Claude Code and OpenCode today; other agents plug in the same way.

bring your own

Your secrets

Stored through a one-time link, never pasted in chat. Each run gets its own Secret, masked in every log and transcript.

never in the chat

Your network policy

Run pods take no inbound traffic and limited outbound. No service-account token, non-root, every capability dropped.

pod security: restricted

Your audit

Every task and every workflow instance keeps its history, step by step. Every run keeps tokens, cost, duration and result.

tasks + workflow instances

Your workspaces

One per team, business unit or customer, each walled off. Three roles in each: owner, admin, member.

walled off by default

the rollout

Start supervised. Earn autonomy.

Start with approvals on every step. As trust grows, let the work run on its own.

01your pilot team

A pilot workspace.

One team, one workspace, one real process. Every step waits for a person to approve it. Nothing runs that nobody saw.

ConvOps · workspace pilotexample

Refund review · approvals on every step

planwaiting for you
changeapproval
testapproval
shipapproval
approvals4 of 4 steps
02your process owner

Teach the first processes.

Describe how the work goes, in the AI tool you already use. ConvOps turns it into a workflow that every AI runs the same way.

Claudeconnected to ConvOps
Refunds over 200: check the order, draft the reply, a lead approves, then send.
workflow created · Refund review · 4 steps · 1 approval
Done. Every refund request now runs this workflow, from any AI tool your team uses.

the same workflow runs in Cursor, ChatGPT and Codex

03you decide

Keep the approvals that matter.

As runs prove themselves, drop the approvals that only slow you down. Keep the ones that guard production, money and customers.

ConvOps · workflow Refund reviewexample

week one

planwaiting for you
changeapproval
testapproval
shipapproval

now

plan
change
test
shipapproval
done
approvals1 of 4 steps · the one that ships
04the schedule

Unattended runs, on a schedule.

Nightly and weekly work runs on its own, each run in its own pod, at the times you set. Each run leaves a record.

schedules · example
000306091215182101:0003:0004:30
22:30sun · UTCnight window
schedulesUTC
  • 01:00Dependency checkevery weekday 01:00not today
  • 03:00Nightly reportevery day 03:00in 4h 30m
  • 04:30Weekly auditmondays 04:30not today
next: Dependency check in 2h 30m
05your platform team

Self-hosted on your cluster.

Your platform team installs one Helm chart in your Kubernetes. Your models, your keys, your network. Nothing has to leave.

your cluster · helm (example)
your Kubernetesyour modelsyour keysyour network
06the whole company

Every team, its own workspace.

Engineering, support, finance, each customer. One workspace each, walled off, with the same governance in every one.

Engineering
fix
reviewapproval
ship
owner · admin · member
Support
triage
replyapproval
close
owner · admin · member
Finance
check
approveapproval
post
owner · admin · member
Customer: Northwind
intake
deliverapproval
report
owner · admin · member

example workspaces · each walled off · same governance

ConvOps · workspace pilotexample

Refund review · approvals on every step

planwaiting for you
changeapproval
testapproval
shipapproval
approvals4 of 4 steps
governance at scale

Same rules, every team.

Gates the AI cannot skip. A history for every task. Three roles. A workspace per team, business unit or customer.

the difference

Scattered AI vs governed AI.

  • Each person prompts the AI their own way.
  • Approvals live in chat, if they happen at all.
  • Agents run on laptops, with whatever access they have.
  • Nobody can say what ran, or what it cost.
  • Knowledge leaves with the people who had it.
  • Each security review starts from zero.

One chart, one values file

Self-hosted installs set the run namespace, pod posture, network policy, time limit and model credentials in one Helm values file.

payload
# install (example)
helm install convops convops/convops \
  --namespace convops --create-namespace \
  -f values.yaml

# values.yaml (example keys)
runs:
  namespace: convops-runs
  podSecurity: restricted
  networkPolicy:
    ingress: none
    egress: limited
  timeLimit: 4h
models:
  existingSecret: model-credentials
example · command and keys are illustrative

An isolated executor

One call names the engine, a pinned version, the model, the time limit and a credential reference. A raw value is refused; you get a one-time link instead.

payload
executors_manage({
  "action": "create",
  "workspace": "engineering",
  "slug": "isolated-sonnet",
  "runner": "convops",
  "config": {
    "backend": "isolated",
    "isolated": {
      "agent": "claude-code",
      "agent_version": "2.1.4",
      "model": "sonnet",
      "time_limit_s": 14400,
      "credential": {
        "kind": "api-key",
        "secret": { "source": "intake" }
      }
    }
  }
})

// response (abridged)
{
  "slug": "isolated-sonnet",
  "credential": {
    "status": "awaiting value",
    "one_time_link": "<sent to you, used once>"
  }
}
example · executors_manage create, isolated backend

Unattended work is a recurrence rule

A schedule fires on a calendar rule, creates the task and runs it on the executor you name. Times are UTC.

payload
{
  "tool": "schedule_create",
  "arguments": {
    "title": "Dependency check {date}",
    "vertical": "development",
    "project": "payments",
    "rrule": "FREQ=WEEKLY;BYDAY=MO,TU,WE,TH,FR;BYHOUR=1;BYMINUTE=0",
    "executor": "isolated-sonnet"
  }
}
example · schedule_create

A workspace per customer

Members join a workspace with one of three roles. Invites wait to be accepted and expire after seven days.

payload
{
  "workspaces_members_manage": {
    "action": "create",
    "workspace": "northwind",
    "email": "lead@northwind.example",
    "role": "member"
  }
}
example · workspaces_members_manage
how we engage

Three steps to a governed rollout.

No big-bang migration. We start on one real process of yours and grow from there.

01you and us

Discovery call

We walk through one process you want governed, and where your code and models need to run.

02your pilot team

Pilot on your process

One workspace, approvals on every step, your team in the loop. Weeks, not quarters.

03your platform team

Self-hosted rollout

Your platform team installs the Helm chart. Teams move over one workspace at a time.

book a demo

See it run your own process.

Bring one process and your security questions. We show ConvOps running it, and where it would live in your cluster.

questions

What procurement asks.

Where does our data live?

Self-hosted, in your own Kubernetes cluster, in the region and under the controls you already run. The engine, the brain, the audit and every run live there, and nothing has to leave your cluster.

Which AI models can we use?

Your own. You bring the model provider and the credentials. Runs use Claude Code or OpenCode today, and the design is agent-neutral: Codex, Kimi and others plug in the same way.

Can we run it without the ConvOps cloud?

Yes. Self-hosted, the whole system runs in your cluster from one Helm chart. Runs reach only the model endpoints, repositories and MCP servers you configure.

How does licensing work?

Self-hosting runs under a commercial licence. We scope it with you on a call, around your teams and your rollout. There is nothing to sign before the pilot shows you it works.

Who supports it?

Neomanex, the team that builds ConvOps. You talk to the engineers who wrote the engine, from the first call through the rollout. Support terms are part of the commercial licence.

How long does a pilot take?

Weeks, not quarters. One workspace, one real process of yours, approvals on every step. You see it run on your own work before you decide anything else.

Do our people have to change their AI tools?

No. Claude, Cursor, ChatGPT and Codex connect over MCP. Your teams keep the tools they use; the process, the approvals and the record move into ConvOps.