Definition
BYOC
BYOC deploys agent infrastructure in a customer-controlled cloud account or VPC instead of only on Islo-managed compute.
Why it matters
Regulated industries and enterprise security reviews often require data and compute inside the customer boundary.
How Islo helps
Islo supports hosted, your cloud, and your customers' cloud deployment modes with the same gateway and workflow primitives.
Deployment modes
Hosted mode runs agent computers on Islo-managed infrastructure — fastest for pilots. Your-cloud mode deploys the runtime inside your VPC so code and data stay in accounts you control. Customer-cloud mode goes further: agent compute runs inside an end customer's boundary when a deal requires it. The workflow primitives — gateway, snapshots, orchestration — stay the same across modes.
What security teams ask for
BYOC answers the questions that stall pilots: where does code run, who holds credentials, and what did the agent touch. With compute in your VPC, existing IAM, logging, and network policies apply. Gateway audit streams to your SIEM. Agents never store long-lived secrets on disk because tokens are injected at egress.
Keep reading
Common questions
Which clouds are supported?
Contact support@islo.dev for current BYOC cloud provider support.
Do I operate the VMs?
Islo manages the agent runtime layer; compute runs in your account per your policies.
Is BYOC required?
No. Many teams start on Islo cloud and move to BYOC when deals require it.
Can end customers require their own cloud?
Yes. Deploy inside your customer's cloud for regulated accounts.
Does pricing change for BYOC?
See /pricing. You pay for compute time; BYOC may have different deployment terms.