Asset managers and allocators
Client books, positions, and operating specifications are sensitive. Uploading operational payloads to a vendor-only cloud can conflict with confidentiality commitments and data-residency policies.
Fontana ships as modular Docker images in one signed platform release. Run managed cloud, dedicated single-tenant, or on-premises behind your firewall; the same governed workflows, controls, and audit evidence in every model.
For regulated financial operations, running the control layer only as someone else's multi-tenant SaaS is not a small inconvenience; it can block legal review, residency commitments, and internal security policy.
Client books, positions, and operating specifications are sensitive. Uploading operational payloads to a vendor-only cloud can conflict with confidentiality commitments and data-residency policies.
Internal security policy and supervisory expectations often require workloads, credentials, and evidence to remain inside approved jurisdictions, or entirely inside the firm's network.
High-volume file intake, reconciliations, and exception evidence cross many clients. Teams need isolation, retention control, and replay without sending that context to an unmanaged third-party plane.
Questionnaires ask where customer data lives, who operates the environment, and whether AI context leaves the estate. Cloud-only answers stall deals that require dedicated or on-premises paths.
Same governed workflows, deterministic execution, lineage, replay, and audit evidence, whether you start in the cloud, isolate a dedicated tenant, or run entirely on-premises.
Multi-tenant or your cloud account
Isolated environment
Full control
All deployment options include the full control layer: knowledge graph context, approval gates, deterministic workflow execution, model governance where enabled, and evidence packs by default, with no feature tiers tied to where you host.
Fontana is engineered for deploy-anywhere operations: pre-built release contents, mount-based updates, and infrastructure declared in Terraform so technology and risk teams can reproduce what they reviewed.
Each platform service ships as a container image. Compose them into one environment without installing application code onto bare hosts beyond boot and orchestration.
A single `fontana-release.tar.gz` drives first boot and upgrades. Replace the release to refresh every mounted service, with no per-service rebuild cycle for operations teams.
The same images and operational footprint run on hyperscaler VMs, dedicated fleets, Kubernetes, or on-premises Docker. Move environments without rewriting the product.
Hardened fleets with health-checked rollouts; dedicated and on-prem paths use the same container entrypoints as managed cloud.
Encrypted storage, scoped secrets, and tenant-aware boundaries, configured for the deployment model procurement approves.
Lineage, approvals, replay material, and audit trails are produced in the run, wherever that run executes.
Every column is the same product. The difference is where compute runs, who operates it, and how data residency commitments are met.