Platform Features

Your accounts. Your servers. One control plane.

Sencai is one control plane for everything you run - the cloud accounts you already pay for, the servers in your own rack, and the workloads on both. It connects to what already exists instead of asking you to rebuild it, then carries the daily work: provisioning, network and access changes, evidence, and cost. Here it is in the order you'd actually use it, with the full capability list below.

Your accounts stay yours

Connect the cloud accounts you already have - eleven providers today, with the European ones treated as first-class rather than exotic - and your own servers alongside them. Nothing migrates: the account, the contract and the billing relationship stay with you, and you can revoke our access at the provider whenever you want. Credentials are encrypted at rest. On-premise and bare metal are targets in their own right here, not a bolt-on to a cloud tool.

See what you actually have

Most estates are bigger than the documentation says. Connect an account and Sencai inventories what is already running - instances, networks, storage, DNS - across every provider and every site, in one list. From there you choose what comes under management, resource by resource, and nothing is rebuilt or moved to get there.

Run it, day to day

Provision, start, stop, resize and destroy instances from one place, with the same workflow whichever provider sits underneath. Firewalls, networks and DNS records are changed live at the provider, so what you see is the current state and not a cached copy of it. A lightweight agent on each server adds monitoring, patching, software inventory and runbooks - incident response written down once, and run the same way everywhere.

Prove what happened - and where it runs

Every action lands in an append-only, hash-chained audit log - tamper-evident and verifiable end to end, which makes "who changed this, and when" a query instead of an investigation. Each organisation is a hard boundary with its own roles and invitations: teams, clients and subsidiaries share the platform, never the data. Sencai is run by an EU company under EU law and platform data stays in European jurisdictions - residency is part of the design, not a clause you negotiate later. That is the evidence NIS2, ISO 27001 and GDPR reviews ask for, and a DPA is on request.

Know the cost before the invoice does

Spend is tracked as it happens, by provider, project and environment - not reconstructed from a pile of billing portals at the end of the month. Set caps and budgets where overspend actually hurts, and get told when something starts drifting rather than when the bill lands. The cost sits next to the resource that produced it, so the number that justifies resizing or switching something off is there when you decide.

What you get

Everything your platform team would build - already built.

Built around what platform teams actually do all day. No bloat, no feature theater.

Infrastructure

Cloud Provisioning

Provision, scale, and retire compute across every provider we integrate - EU-native (Hetzner, OVHcloud, Scaleway, UpCloud) and global (AWS, Azure, Google Cloud, DigitalOcean, Vultr, Akamai/Linode, Oracle Cloud) - with managed databases, object storage, and DNS on the providers that offer them, from a single API and UI.

Import & Discovery

Already running in the cloud? Connect an account and Sencai discovers your existing VMs, networks, and storage - then promotes them into managed resources without re-provisioning anything.

Fleet Management

A lightweight agent for cloud instances, on-premise, and bare-metal servers - monitoring, patch management, software inventory, and a browser SSH terminal. Kubernetes clusters join the same fleet via Helm.

Day-2 Operations

Runbook Automation

Codify your incident response once, run it everywhere. Approval-gated runbooks executed by the fleet agent turn 3 a.m. firefighting into a reviewed, one-click action.

AI Operations

Automated root-cause analysis, alert correlation, and remediation recommendations powered by a pluggable LLM backend with per-tenant cost guardrails.

Monitoring & Alerting

Centralized metrics for CPU, memory, disk, and network across your entire estate, with alert routing to email, Slack, and webhooks.

Trust & Compliance

Security & Compliance

CVE scanning on container images, CIS benchmark and Lynis hardening checks on VMs, automatic SSL/TLS renewal, and a policy engine with governance scoring - NIS2 evidence collection built in.

Immutable Audit Trail

Every action lands in an append-only, hash-chained audit log - tamper-evident and verifiable end-to-end. Exactly the evidence trail NIS2 and GDPR reviews ask for.

Identity & Access

Single sign-on with Microsoft Entra ID and Google Workspace, SCIM provisioning, two-factor authentication, and fine-grained roles with just-in-time elevation - enterprise identity from day one.

Business & Teams

FinOps

Real-time spend by service, project, and environment. ML-flagged cost anomalies, right-sizing recommendations, and budget alerts - with automated actions (Autopilot) on the roadmap.

Developer Platform

Go, Python, and TypeScript SDKs, a GraphQL API, and Terraform export of everything you manage - automate Sencai the same way you automate your infrastructure.

Built for MSPs & Agencies

Manage every client organisation from one login. Scoped, time-boxed cross-tenant access with approval workflows keeps client boundaries intact.

Ready to take control of your cloud?

Join the teams building on European-sovereign infrastructure. Start today - no sales call required.