Skip to main content
Your organization’s agents run on xpander, so control applies as the agent acts: every model call and every skill call is checked against the agent’s policies, given its credential at that moment, counted against its budget, and recorded under the person who asked. Security review happens once. Every new agent starts inside the skills, models and policies you approved, and inherits that review.

What you control

Where xpander runs

Every connection that leaves your perimeter in a self-hosted install is optional and under your control. The egress table on the air-gapped page lists each one, when it is used, and the setting that turns it off or points it inside.

In this section

Deploy

Deployments, prerequisites, install, verify, upgrade, scale.

Integrations

AI gateway, AI vendors, MCP gateway, desktop AI clients, Slack workspace, Microsoft Teams tenant, email, identity providers, vault providers, EKS clusters, the data layer, file storage.

Licensing and identity

The two-file license, renewal, and single sign-on with your identity provider.

Security and compliance

Architecture per deployment, certifications, data handling.

Access control

Members, roles, API keys and audit.