SuperSoft 3.0 Sovereign Cloud-Prem, policy agents, model routing and prototype import — read the release
Platform Governance Deployment Use cases Stack Log in Book a demo
The governed system factory / built for regulated ASEAN

Describe the system.Keep the perimeter.

Business teams build production AI systems on your own data — CRM, collections desks, approval flows, customer portals. Your data, code and inference never leave your network. IT and Risk keep identity, integrations, policy and audit.

Collections Ops · plain language

Build me a collections desk: segment overdue accounts, log promises to pay, and escalate anything past 90 days to a supervisor.

Data model Accounts, promises-to-pay, dispute log ✦ native
Workflow Segment → dial → capture PTP → escalate ✦ native
Surface Agent console, supervisor board, API ✦ native
Controls RBAC, row-level masking, full audit trail ✦ sealed

Inference, database and code stay inside this line.

Built for the operators regulators actually inspect

BanksInsurersTelcosConsumer finance UtilitiesGovernment agenciesBPO & shared services
The problem / shadow AI

Every AI app you can't see is an incident waiting to be filed.

Your teams are already building. They paste production data into consumer chat tools, spin up databases nobody owns, and wire integrations with credentials nobody rotated. None of it appears in your asset register.

Data leaves

Customer records go to third-party models

Names, national IDs, balances and call transcripts sent to endpoints outside your contracted processors — often outside your jurisdiction.

Access drifts

Credentials live in prompts and notebooks

Long-lived keys pasted into tools with no rotation, no scoping and no record of which app used which system, when.

Audit fails

No evidence when the examiner asks

You cannot produce who built the app, what it can reach, who approved it, or what it did last Tuesday at 14:20.

Figure 01 / where the data actually goes today
INSIDE THE BANK OUTSIDE YOUR CONTROL Analyst laptop consumer chat tool Ops workbook macros + pasted keys Weekend prototype nobody owns it SECURITY PERIMETER names · IDs · balances long-lived credentials no log, no owner Third-party model unknown jurisdiction External database outside your DR plan Unlisted host not in the asset register

Three crossings. None of them appear in an audit export.

Platform / the factory floor

A software factory for business teams. Signed off by Security and Risk.

Import prototypes from Claude, Lovable, Replit or a Git repo. Build with the SuperSoft MCP. Run it on your own stack — your database, your identity provider, your inference, your logging.

Composer

Plain language in, whole system out

Say what the system needs to do. SuperSoft returns the data model, screens, workflows and permissions as one native module — not four disconnected pieces to integrate later.

Import

Take prototypes to production

Bring in what your teams already built on their laptops. SuperSoft rehosts it inside the perimeter, attaches real auth, and puts it under change control.

Workflows

Agents that run on a schedule

Background automations, queue workers, scheduled reconciliations and escalation agents — all with the same approvals and audit trail as the screens.

Lifecycle

Version, promote, roll back

Dev, staging and production environments with diffs, approvals and one-click rollback. Every release is attributable to a person and a ticket.

Every module deploys native alongside the group's other platforms

SuperOneSuperCallSuperCenterSuperFeel SuperKnowSuperYooSuperQASuperSage
Governance / integration control layer

AI apps never touch your systems directly.

Every call from every app passes through SuperSoft. Authentication is enforced, secrets are abstracted away from the builder, access controls are inherited from your directory, and each interaction is written to an immutable log.

Identity

Your directory decides

SSO and SCIM from the identity provider you already run. App permissions inherit group membership, so a leaver loses access everywhere at once.

  • Okta, Entra ID, Google Workspace
  • Row and column-level masking
  • Just-in-time elevation with approval
Secrets

Builders never see credentials

Connections are configured once by IT and exposed to builders as named capabilities. Keys live in your vault and rotate on your schedule.

  • Vault, AWS/GCP Secrets Manager, HSM
  • Scoped, revocable service identities
  • No credential ever enters a prompt
Evidence

Audit that survives an inspection

Who built it, who approved it, what it reached, what it changed, and what the model was asked. Exportable in the format your examiners accept.

  • Immutable, timestamped, exportable
  • Prompt and tool-call lineage
  • Retention aligned to your policy
Figure 02 / every call is brokered, none are direct
AI-BUILT APPS Collections desk Dispute triage Partner portal Nightly agent SuperSoft integration control layer MANDATORY · NON-BYPASSABLE Authenticate API and MCP, per call Abstract secrets builder never sees a key Inherit permissions from your directory Log everything immutable, exportable SYSTEMS OF RECORD Core banking CRM Data warehouse Telephony MCP servers

The direct path is refused at the network layer, not by policy documentation.

Deployment / sovereign cloud-prem

SuperSoft runs inside your cloud. Not next to it.

The managed experience of SaaS, with the containment of on-premise. Your virtual private cloud, your sovereign region, or a rack in your own data centre — the control plane manages, the data plane stays home.

Inference

Your models, your endpoint

Bedrock, Vertex, Azure OpenAI, or open-weight models on your own GPUs. Prompts and completions never transit a SuperSoft endpoint.

Identity

Your IAM roles

Workloads assume roles you define. SuperSoft has no standing credential into your environment and no break-glass path you didn't grant.

Network

Your network policy

Private subnets, egress allow-lists, PrivateLink and existing firewall rules apply unchanged. Nothing new is exposed to the internet.

Data

Your databases

Apps provision into Aurora, Cloud SQL or your own Postgres inside the perimeter — never an external managed database you don't control.

Residency

Data stays in-country

Deploy per jurisdiction so Malaysian records stay in Malaysia and Indonesian records stay in Indonesia. Residency is a deployment topology, not a promise in a contract.

Regulation

Mapped to the frameworks you file against

Control mappings for BNM RMiT, PDPA, MAS TRM, OJK and GDPR, with the evidence artefacts pre-built so your first audit isn't a project.

Continuity

It keeps running without us

Source-available escrow and a documented exit path. If the relationship ends, your systems and data remain yours and remain operational.

Figure 03 / split plane topology — we manage, you contain
SuperSoft control plane our infrastructure CONFIG · UPDATES · HEALTH TELEMETRY No customer data. No standing credential. YOUR VPC · YOUR SOVEREIGN REGION SuperSoft data plane YOU HOST IT · WE MAINTAIN IT App runtime screens, APIs, portals Workflow engine agents, schedules, queues Policy agents scan, flag, quarantine Your inference Bedrock · Vertex your own GPUs Your database Aurora · Cloud SQL your own Postgres Your secrets Vault · KMS HSM-backed Your logs SIEM sink your retention ENFORCED BY YOUR EXISTING CONTROLS Your IAM roles · your network policy · your egress allow-list · your private subnets

Prompts, records, code and completions never cross the dashed line.

Economics / Superforce model router

Stop paying frontier prices for routine work.

Most tasks in an internal system are not hard. Formatting a record, drafting a follow-up, classifying a dispute reason — open-weight models handle these well. The router scores each task and sends it to the cheapest model that clears the quality bar, reserving frontier models for genuine reasoning.

You set the bar, the budget and the fallback. The router publishes cost per task so finance can see where the spend actually goes.

See a routing report

Routed volume · trailing 30 days

Open-weight71%
Mid-tier21%
Frontier8%
Cost per task
−34%
Quality gate
held
Figure 04 / one harness, three tiers, one quality gate
Task from an app Score it reasoning depth, context, risk class Open-weight formatting, extraction, drafts 71% Mid-tier summarise, classify, plan 21% Frontier multi-step reasoning, code 8% Quality gate PASS FAILS THE GATE → RETRY ONE TIER UP, AUTOMATICALLY

You set the gate, the budget and the fallback. The router publishes cost per task, per app, per team.

Use cases / what teams build first

Retire the spreadsheet. Replace the seat licence.

These are the five patterns that show up in almost every deployment, drawn from eighteen years of running regulated operations across seven ASEAN markets.

Pattern A

Productionise the prototype

Your analyst built something good in a weekend. Import it, attach real identity and data, and ship it to the floor without a rewrite.

Pattern B

Kill the shared spreadsheet

The exceptions workbook that runs a department becomes a governed app with roles, approvals and a log of every change.

Pattern C

Replace SaaS you've outgrown

Build the twenty percent of the tool you actually use, fitted to your workflow, at a fraction of the per-seat bill.

Pattern D

Ship a customer portal

Give customers, dealers or partners a self-service surface — embedded in your existing portal or standing on its own.

Pattern E

Run background agents

Overnight reconciliations, queue triage, document extraction and escalation bots that work while the floor is closed.

Start here

Pick one process. Two weeks.

We scope a single live process with your team, ship it into your perimeter, and let the audit trail make the case for the next ten.

Book the scoping call
Control plane / SuperSoft MCP

Watch every app. Revoke in one move.

The control plane exposes your whole estate through MCP, so your security team can ask questions in plain language and act on the answer. Which apps use a vulnerable dependency. Who can read the salary table. What changed since Friday.

Policy agents run continuously against the same interface — flagging drift, quarantining an app, and notifying the owner without waiting for a human to notice.

14:02scan 214 apps · 3 flagged
14:02warn dispute-triage · dependency below patch floor
14:03halt partner-uploads · egress to unlisted host
14:03act quarantined · owner notified · ticket OPS-4471
14:07ask "who can read customer_pii?"
14:07ans 9 users · 2 apps · 1 role · export ready
Architecture / what you rent, what you own

The layers that compound are the ones you keep.

Compute and base models are commodities you rent. The layers below the line — your data, the actions your teams take, and the judgment that transfers between them — are the ones that get more valuable every quarter you run them.

L1 · RENTEDSovereign computeIn-country GPU capacity, or your existing cloud region.
L2 · RENTEDBase modelsOpen-weight and frontier, selected per task by the router.
L3 · CONFIGUREDIndustry corpusRegulatory text, product taxonomies and market conventions.
L4 · YOURSCompany dataYour records, in your database, inside your perimeter.
L5 · YOURSAction & outcome dataWhat was decided, what was done, and what happened next.
L6 · YOURSJudgment & transferPatterns that generalise from one process to the next.
L7 · YOURSDeployed surfacesThe consoles, portals, APIs and agents your teams run on.
In production / what operators say

“The question was never whether business teams would build software. It was whether we could see it. SuperSoft gave us a path from prototype to production that our risk committee could actually sign.”

Group CISORegional banking group

“Sixty-one apps across eleven departments, all inside our own VPC. The audit export took four minutes. The previous answer to that request took three weeks.”

Head of IT InfrastructureConsumer finance, Malaysia
18 yrs
of regulated operations behind the platform, not a founding date on a slide.
7
ASEAN markets with in-country deployment and local support hours.
176
enterprise customers running critical operations on the group's platforms.
0
bytes of your customer data leaving your perimeter, by architecture.

What should your team build this month?

Bring one process that runs on a spreadsheet today. We'll scope it, build it inside your perimeter, and hand you the audit trail.