FOR REGULATED INDUSTRIES
The Compliance-Ready Internal Developer Portal and Platform
What tension links banks, insurers, healthcare and life sciences, energy and utilities, telecom, government contractors, and critical infrastructure operators? Modernizingg infrastructure delivery without breaking the controls the regulator wants to see. Cycloid gives your teams a turnkey Internal Developer Portal and Platform that enforces policy at submission time, generates the audit trail automatically, and runs where the rules say it must – on-premises, air-gapped, dedicated SaaS on a sovereign cloud, or a hybrid of the three.
Where Regulated IT Breaks Under Audit
The operating model most regulated IT teams inherited was built for a slower delivery cadence and a paperwork audit. It doesn’t survive contact with 2026.
Manual change control can't produce evidence
Environment provisioning takes days. Every infrastructure change is a ticket, a Jira link, an email approval, and a spreadsheet entry. When an examiner asks who approved what and when, the trail lives in five systems and someone’s inbox. DORA’s Register of Information doesn’t fill itself.
Policy lives in documents, not pipelines
Security, network segmentation, data-residency, and cost rules sit in Confluence pages and institutional memory. Enforcement depends on which reviewer sees the change. Two identical requests get different outcomes. NIS2 wants proof the controls are applied – not proof they exist.
Shadow IT is now a reportable incident
When the official path takes weeks, developers go direct to cloud consoles. Unmanaged resources become compliance blind spots: inconsistent configurations, incomplete audit trails, unallocated cost, and – in healthcare or financial services – a plausible data-residency breach nobody logged.
Hyperscaler concentration is a DORA problem
Finance demands answers on cloud spend. Regulators demand a credible exit strategy from any Critical ICT Third-Party Provider. Platform teams that can’t show which departments, projects, and workloads run where can’t answer either question.
Data residency isn't a preference
Patient data, cardholder data, classified workloads, and GDPR-scoped personal data all come with locality rules. Cloud-only platforms that force architectural compromises are not an option.
One Platform. Compliance by Construction. Delivered in Weeks.
Cycloid is a unified Internal Developer Portal and Platform built for organisations that need governance without gridlock, self-service without shadow IT, and cost visibility without a separate FinOps tool. It works with your existing Git providers, CI/CD, identity provider, and infrastructure – not against them.
Recognised as a European IDP leader by IDC (November 2025), Cycloid bridges DevOps, platform teams, developers, and FinOps/GreenOps - with sovereignty and sustainability as product properties, not marketing angles.
Why Regulated Organisations Choose Cycloid
Sovereign by Design
European-born, sovereign-by-design, and deployable self-hosted, air-gapped, on dedicated SaaS (AWS, Azure, GCP, Scaleway, OVH, Outscale), or on bare metal. Governance scales without adding headcount: Policy as Code, RBAC with segregation-of-duties enforcement, approval workflows, and mandatory tagging reject non-compliant requests at submission time. StackForms let any team member self-serve infrastructure in minutes, no Terraform required.
Governance That Scales
Built-in FinOps and GreenOps deliver cost estimation before every deployment, cross-cloud spend visibility, and carbon footprint tracking. Cycloid is cloud-agnostic and open-source-founded, integrating with GitHub, GitLab, Terraform, Ansible, Helm, ArgoCD, Datadog, and the identity provider you already run. Deliver 80% of best practices out of the box, operational in weeks, not the 12-24 months a DIY build typically consumes.
Deploy Cycloid Your Way
Deployment Model
How It Works
Best for
Data Residency
Regulation Fit
All Cycloid modules deployed on your infrastructure. Cycloid has zero access post-deployment
Air-gapped environments, highest sovereignty requirements, classified workloads
Fully on-premises. Your network, your rules
SecNumCloud alignment, classified/defence, HIPAA on-prem, 21 CFR Part 11 GxP, national-security workloads
Cycloid deploys and operates all modules on a dedicated cloud account you choose (AWS, Azure, GCP, Scaleway, OVH, Outscale)
Teams that want managed operations with infrastructure isolation
Isolated cloud account. Your provider, your region
DORA CTPP-appropriate isolation, EBA outsourcing guidelines, GDPR EU-region hosting
Control plane as SaaS, Concourse workers in your environment for workload proximity
Organizations that need application workloads close to on-prem systems
Workloads stay local. Control plane is managed
HIPAA data-locality patterns, financial services on-prem core with cloud edge, healthcare PHI on-prem
Fully managed by Cycloid. Fastest time to value
Teams prioritizing speed and minimal operational overhead
Cycloid-managed infrastructure. EU-hosted available
SOC 2 / ISO 27001 workloads, regulated organisations with lower-classification environments
1.
Platform Teams Build the Compliant Service Catalog
Create reusable Stacks – pre-approved infrastructure templates that embed encryption baselines, network segmentation, data-residency rules, and cost boundaries. Use Infra Import to reverse-engineer Infrastructure as Code from existing manually-deployed resources, so day one is your real estate, not a greenfield lie.
2.
Governance Is Enforced Automatically
InfraPolicies validate every deployment against your control framework at submission time – SOX segregation of duties, DORA change controls, NIS2 configuration standards, PCI-DSS scoping. RBAC scopes access by team and role. Quotas limit resource consumption. Approval workflows route sensitive changes to the right decision-makers. Untagged or non-compliant resources are never created.
3.
Developers Self-Serve Through Golden Paths
Users pick services from the catalog, customise options through StackForms, see cost and carbon estimates plus control checks, and deploy – no Terraform required. Forms adapt: dropdowns filter based on previous selections, advanced fields display conditionally, and cloud accounts auto-complete via API. The compliant path is the easy path.
4.
Every Action Is Auditable
Asset Inventory tracks every resource across public and private clouds. InfraView maps your infrastructure topology visually. Cloud Cost Management and Cloud Carbon Footprint deliver FinOps and GreenOps reporting with department-level allocation. Complete audit trails export directly into the evidence packages examiners ask for. GitOps makes Git the single source of truth for both application and infrastructure state, so every change is a pull request with an approver, a diff, and a commit hash you can tie back to a ticket.
Public Sector Capabilities at a Glance
Compliance & Governance
On-premises / air-gapped deployment
Dedicated SaaS on sovereign clouds (Scaleway, OVH, Outscale)
SSO/SAML (Okta, Entra ID, SAML 2.0) with segregation-of-duties enforcement
RBAC with organisational scoping
Complete audit trails and evidence-package export
Approval workflows with recorded reviews
Multi-factor authentication
Policy as Code (InfraPolicies) for DORA, NIS2, SOX, PCI-DSS, HIPAA controls

Controlled Self-Service & Developer Experience
StackForms self-service portal
Service catalog (Stacks) with encoded compliance baselines
Infra Import from existing resources
GitOps-first architecture
CI/CD orchestration (native and integrations)
Data-residency enforcement via mandatory tags
Cost estimation before deployment
Multi-tenancy for departments and subsidiaries
Plug-in extensibility

FinOps & GreenOps
Cloud Cost Estimation (pre-deploy)
Cloud Cost Management (cross-provider)
Cloud Carbon Footprint tracking for green procurement mandates
Asset Inventory with owner mapping
InfraView topology visualisation
Custom pricing / ELA rate support
Quota management
Department-level cost allocation

Integration & Openness
AWS, Azure, GCP, VMware, bare metal
Sovereign clouds: Scaleway, OVH, Outscale
GitHub, GitLab, Azure DevOps, Bitbucket
Terraform, Ansible, Helm, ArgoCD
Jenkins, GitHub Actions, GitLab CI/CD
Datadog, Prometheus, Grafana
REST API (Swagger-documented)
MCP Server for AI and natural-language operations

A sovereign, compliance-ready Internal Developer Portal and Platform, operational in weeks. No vendor lock-in. No architectural compromises. Audit evidence on demand.
