Sovereign AI

Your models. Your data.
Your perimeter.

Train models, build datasets, and serve endpoints all inside your own cloud or datacenter, governed and owned by you. Your data never transits Union's infrastructure. Not proxied, not cached, not “encrypted in transit through us”. It just never leaves.

Control plane

Self-hosted control plane is an enterprise plan, where nothing leaves your infrastructure. Explore Enterprise with us →

References, never payloads

A Guarantee You Can Inspect,
Not a Promise You Have to Trust.

Most platforms ask you to trust their process. Union's isolation is topological, not behavioral: the data path physically does not pass through the control plane, and you can verify it — in the Helm charts, the tunnel config, and the Envoy filter chains.

01

References, never payloads

The control plane stores run IDs, schedules, and artifact references. Inputs, outputs, logs, code bundles, and reports live in your object store and are served by a dataproxy inside your perimeter.

02

Outbound-only connectivity

Your cluster initiates the tunnel. No inbound ports, no firewall changes, no VPN peering into your VPC. Every request is authenticated and authorized by an Envoy router that runs on your side of the line.

03

Your keys, your custody

Data is encrypted with keys you hold in your KMS. Compromising Union's infrastructure would still not reach your data — an attacker would also need your cloud IAM and your keys.

04

Faster, not slower

Direct-to-DataPlane isn't a security tax. Reads and writes go straight to your object store, so the secure path has lower latency and lower egress cost than proxying through a vendor.

From the announcement: Zero-Trust Security Architecture

In the console

The Lock Is in the Product,
Not the Brochure.

Every surface in the run view carries a lock — inputs, outputs, logs, reports, code. Hover over one and the console tells you exactly where the bytes came from: served by your data plane, through the Direct-to-DataPlane tunnel, never entering the control plane in any form.

The URL under the lock is your data plane's domain — the console fetches these bytes from your infrastructure, not Union's.

train_grpo ✓ Succeeded Triggered
Run: ufe486be308c71f1d · Task: trainer.train_grpo · Cluster: oc-production
Summary Logs Reports Code
Setup 1s Succeeded 3m 25s
Input
profile_name (string)*
smoke
dataset (file)*
⛁ rl-tasks-dataset@uwbwvdrsf2gzj27gmvgp-5j…
s3://union-oc-production-demo-raw/at/demo/model-factory/development/…/rl_tasks_merged.parquet
Output
o0 (directory)*
⛁ policy-checkpoint@ufe486be308c71f1d-a0-1
s3://union-oc-production-demo-raw/3g/demo/model-factory/development/…/policy-checkpoint
Run Logs Kubernetes Events Cloudwatch Logs ↗
Filter logs Timestamps
■Sep 02 23:12:03.256[flyte] WARNING Flyte runtime started for action a0 with run name uqgmjb48ndh88qhp8zcl
■Sep 02 23:12:05.561[flyte] WARNING It is recommended to use a minimum of 2 replicas, to avoid starvation. Options: increase concurrency, increase replicas, or turn off reuse for the parent task.
■Sep 02 23:13:15.095[flyte] WARNING Flyte runtime completed for action a0 with run name uqgmjb48ndh88qhp8zcl
main ⟳ Refresh | Off ▾
GRPO training — grpo-smoke-ufe486be308c71f1d
10
step
0.200
mean reward
0.00%
pass rate
nan
loss
reward (max 1.2)
▪ mean reward▪ pass rate
Code
▾ Files
trainer.py
1import flyte
2from flyte.clustered import ClusteredTaskEnvironment, TorchRun
3 
4trainer = ClusteredTaskEnvironment(
5 name="trainer", resources=flyte.Resources(gpu="A100:4"),
6 replicas=4, nproc_per_node=4, runtime=TorchRun(),
7)
8 
9@trainer.task(trigger=flyte.OnArtifact("rl-tasks-dataset"))
10async def train_grpo(dataset: flyte.io.File) -> flyte.io.Dir:
11 …
The whole factory, inside

Everything a Frontier Stack Needs.
Nothing Leaves.

Sovereignty is worthless if it costs you capability. Union runs the full loop — data, training, evals, serving — on your GPUs, in your VPC, with the same event-wired automation as any managed platform.

Train at cluster scale

Multi-node distributed training with ClusteredTaskEnvironment — torchrun across your own GPU nodes, checkpoints in your object store, OOM recovery mid-run.

Create data durably

Fan out synthesis and filtering across thousands of spot containers with flyte.map. Every element checkpointed; every dataset a versioned artifact with lineage.

Serve inside the VPC

Model endpoints, batch inference, and apps run on the same runtime that trained the model — behind your load balancer, reachable only from your network if you choose.

RBACleast-privilege across users, systems, and projects
SSO / OIDCyour identity provider, plus API keys and service accounts
Secretsnever readable back through the API, never transit the control plane
Audit logsevery action on the record, gated by RBAC
SOC 2 Type IIsecurity, availability, processing integrity — plus ISO 27001 alignment
HIPAA-readydesigned for regulated workloads from day one
Your secrets, your keys, your code

None of them ever leave
your perimeter.

“References, never payloads” is a claim you can check asset by asset. Here is every thing a run touches, and which plane actually holds it.

Asset Your data plane Union control plane What the control plane sees
Isolated between teams, not just tenants

Encrypted with your keys.
Isolated between your teams.

The perimeter isn’t only the outer wall. Inside it, projects and domains are real boundaries: separate namespaces, separate service accounts, separate buckets and secrets, and network policy that keeps one team’s workloads off another team’s services.

  • In transit — TLS everywhere, and the data path is a tunnel your cluster dials out to. No inbound connection is ever opened into your network.
  • At rest — object storage, metadata, and snapshots encrypted with keys you own and rotate.
  • Between teams — per-project namespaces and service accounts, scoped secrets, and network policy between workloads.
  • Between tenants — each tenant’s work is scheduled by its own owner, so a million-action backfill from one team can’t slow a five-task run from another.
your cloud perimeter
pick a team to see what it can and cannot reach
Full observability

Every signal in one place.

Every action has a deterministic name, and the logs, metrics, errors, inputs, outputs, and cost of a step all hang off it. There is no correlation step, so the queue view, the cost rollup, and a task’s own report are all reading the same state the scheduler runs on.

acme ✓ Active
Cluster pool
default
Clusters connected
1 of 12
Queues connected to pool
11
Queue Overview
Depth
8 / Unlimited
Runs in flight
6 / Unlimited
Actions in flight
8 / Unlimited
Queue activity
Actions in progress by phase (per 5 min)
Running Waiting for resources
Throughput (per 5 min)
Completed
Welcome, Acme!
Activity across every project in this organization.
Actions executed
5,710
↓ 8.3% vs prior period
Union saved youlast 24h
57
actions served from cache or recovered · 1.0% of everything you ran
Runs completed
2,612 ↓ 2.4%
97.9% succeeded
Active apps
52
52 replicas serving now
Active users
17
people who shipped work
Actions over time

GRPO + LoRA training progress

✓ complete
Objective

Token-level clipped-ratio GRPO. The importance ratio comes from vLLM sampling-time logprobs against the adapter-disabled base, which is what makes the one-step-off-policy pipelined training sound.

Latest iteration
1.027▼ 0.073Mean reward
83.3%▼ 6.8%Accuracy
85.9%▲ 25.0%Eval accuracy, held out · base 60.9%
0.0002▲ 0.0001Mean loss
Reward & correctness vs. iteration
0.500.640.770.911.051.18 012345678910111213141516171819
mean reward accuracy format rate iteration →

Reports are published by the task itself, so “how did it do” has an answer in the same place as “did it finish”.

Enterprise grade Flyte

Open source at the core.

Union is built on Flyte, the open-source AI runtime we create and maintain under the Linux Foundation AI & Data.

A Linux Foundation AI & Data Project
4000+ companies using Flyte today
18M+ Flyte SDK downloads

Draw the Perimeter.
Keep Everything Inside It.

Bring one workload — training, data, or serving. We'll run it inside your cloud this week, and you can inspect exactly what the control plane sees: references, and nothing else.