Four layers. One governed platform.
Nebulous separates how people engage, how work is orchestrated, how context is grounded and how data is held. Each layer is independently governed, and the whole platform runs inside your own cloud account.
User experience layer
Interactive interfaces and engagement channels for the people who do the work: case workspaces, approval queues and the channels your customers and staff already use.
Every material decision surfaces here for a person to approve, reject or amend, and each decision is recorded against the run.

Orchestration platform
The core engine: multi-agent processes, task routing and automated execution. Work is decomposed across specialist agents, routed by rules you control, and executed only through tools approved for each agent.
Every step carries a risk tier. Anything material pauses for a person, and anything uncertain stops rather than guesses.

Context layer
Your policies, product documents and reference material become structured context an agent can reason over, with the exact clause quoted on every answer.
Enterprise metadata and real-time retrieval graphs keep that context current, so answers reflect the policy in force today rather than a stale copy.

Data layer
State management and the records themselves. You copy the data you choose into a database inside your own account, on your own schedule.
Agents read it through controlled, read-only connections and can never change it. Core systems are never called directly, and every read is recorded.

Nebulous Studio and Nebulous Cloud.
Runs in your environment
Your platform team configures agents and approval thresholds, monitors runs in flight, oversees the approval queue, tests changes safely and reads system health - all inside your own tenancy.
Where agents are authored
Agents are designed, sealed and versioned here, then delivered as releases your systems verify before anything runs. Licences and seats live here; client data and client users never do.
What your architecture review
will want to know.
- Deployment model
- Single-tenant, installed in your own cloud accountOne installation per institution. No shared runtime, no shared database, no shared identity.
- Hosting
- AWS first, ap-southeast-2 (Sydney)Bedrock, ECS Fargate, Amazon RDS and Step Functions. Every service containerised, so the installation can move without a rebuild.
- Identity
- Self-hosted OIDC with multi-factor authenticationOne realm per institution, administered by you. Federation to your own identity provider on request.
- Data handling
- Extracts pushed into a database in your accountRead-only, governed access. Core systems are never called directly and nothing is copied out.
- Model layer
- Amazon Bedrock behind a provider interfaceModels are pinned per agent and can be changed without rebuilding an agent.
- Records
- Tamper-evident, append-only, held by youEvery run replayable end to end. Nothing is exported to the vendor at any point.
- Delivery and support
- Sealed releases; support by ticketConfig update or on-site install. No standing vendor access to your environment.
Security, governance and observability
wrap every layer.
Security
Sign-in you host, with multi-factor authentication. Every request permission-checked at the gateway and again at the service. Every release seal verified before it runs.
Governance
Every model input and output screened. Risk tiers on every action, a person on every material decision, and fail-closed behaviour whenever something is uncertain.
Observability
Every run recorded end to end in a tamper-evident, replayable record - readable by your risk and audit teams, inside your tenancy only.
Want the architecture deep dive?
We walk risk, security and architecture teams through the full design - identity, permissions, release sealing and the audit record - under NDA.