Platform

Cloud and the hardware you already own, one control plane

Most infrastructure platforms treat on-premise as a special case bolted onto a cloud-first product — a separate agent, a separate screen, a worse experience. Sencai built it the other way round: the fleet agent behaves identically on a cloud instance and on a server sitting in your own rack, and enrollment never asks whether a machine has a cloud account, because plenty of real infrastructure doesn't. If you run owned hardware alongside cloud capacity, entirely instead of it, or somewhere in between, the same control plane, the same audit trail, and the same runbooks apply everywhere.

The same agent on every Linux box

Install the fleet agent on a Linux server — a cloud instance or a physical machine sitting in your own rack — and it behaves exactly the same way regardless of where that server actually lives. Continuous monitoring, patch management, software inventory, and runbook automation all run through the identical agent, with the identical approval gate before anything executes. Write an incident response procedure once, as a runbook, and run it against a Scaleway VM today and a colocated bare-metal box next week without touching the procedure itself — the agent doesn't change behavior based on what it's sitting on top of. A separate, purpose-built agent handles Kubernetes: install it in-cluster and it reports inventory and lets you manage that cluster from the same dashboard as everything else, cloud or on-premise. Nothing about either agent asks which provider — or whether there's a provider at all — before it starts reporting. You get one download, one install process, one place to look, whether you're rolling it out across a fleet of cloud instances or a handful of servers under a desk.

No cloud account required to start

Enrolling a server doesn't require linking it to a cloud provider account, because a lot of on-premise hardware doesn't have one. A rack server, a colocated box, an old workstation pulled into service as a build machine — each enrolls directly, on its own, with no cloud credential anywhere in the process. Cloud-connected instances and standalone hardware sit in the same fleet view afterward: filterable, taggable, and managed through the identical set of screens and runbooks. That's a deliberate design decision, not an oversight — the platform doesn't assume every managed server traces back to a cloud account, because plenty of real infrastructure never will. If your estate is entirely on-premise today, with no cloud account connected at all, the fleet agent, the audit log, patching, and runbook automation all work exactly the same as they would for a team running purely on hyperscaler cloud. Hybrid isn't a special mode bolted on top — it's the default assumption the platform was built around.

Cloud accounts connect — nothing migrates

For the cloud side of a hybrid estate, Sencai connects to accounts you already have across eleven providers — Hetzner, OVHcloud, Scaleway, UpCloud, AWS, Azure, Google Cloud, DigitalOcean, Vultr, Akamai/Linode, and Oracle Cloud. Nothing migrates when you connect one. The account, the contract, and the invoice stay exactly where they already are with the provider; Sencai holds an encrypted credential and nothing more, and you can revoke that access at the provider at any moment, immediately, without contacting anyone here. The moment an account connects, its instances, networks, storage volumes, and DNS zones show up in inventory automatically — no migration step, no forced adoption, no waiting for a maintenance window. From there it's resource by resource: you decide what comes under active management and what stays as a read-only entry in the inventory for now. See the integration pages — starting with Hetzner — for what each connected provider supports today.

Or let Sencai carry the cloud contract

If you'd rather not hold a separate contract with every provider you touch, Sencai can provision and bill cloud capacity under its own accounts on your behalf. That's one contract and one invoice instead of many, with the provider's own cost passed through plus a 2% margin, shown as its own line item on the statement — never folded invisibly into a bigger number. The two models aren't a fork in the road you pick once and live with. A single organisation can run BYOC accounts for infrastructure it already has and add Sencai-managed capacity for whatever comes next, or start managed and bring existing BYOC accounts in later — both sit in the same inventory, under the same policies, without splitting the estate across two tools or two audit trails. Combine that with on-premise hardware enrolled directly, and one organisation can legitimately span owned racks, a BYOC AWS account opened years ago, and capacity Sencai provisions and bills today, without anyone needing to remember which is which when they open the dashboard.

One inventory, one policy, wherever the hardware sits

Cloud instances, on-premise servers, and Kubernetes clusters land in the same inventory, under the same role-based access control, the same single sign-on — Microsoft Entra ID or Google Workspace, with SCIM provisioning for both — and the same just-in-time elevation workflow for anyone who needs temporary elevated access with an approval attached. There's no separate console for the data-centre estate and no second login for the team that manages physical hardware. A security review or an internal access audit doesn't need a different answer for servers in a colocation facility than it does for instances in a cloud region — it's the same fleet, the same roles, the same approval trail, asked and answered once. See security and compliance for how that access model holds up under review. For a team running hybrid specifically because some workloads can't leave a particular building, that consistency matters as much as the coverage itself: policy doesn't quietly loosen at the edge of the network a cloud console can't see into.

An audit trail that doesn't stop at the cloud boundary

Every action across the fleet — cloud or on-premise — writes to the same append-only, hash-chained audit log. Who patched a rack server last Tuesday, who ran a runbook against a bare-metal box at 2 a.m., who touched a firewall rule on a cloud instance: it's a query against one log, not a reconstruction project pulled together from a hypervisor, a ticketing system, and someone's memory. Sencai doesn't hold ISO 27001 or SOC 2 certification, and says so directly rather than implying otherwise. What it hands a security reviewer instead is the evidence those certifications are usually a proxy for: an exportable audit trail, records of processing, a published sub-processor register, a data-residency statement, and a published Data Processing Agreement. For a team keeping certain workloads on-premise specifically for data-residency reasons, that evidence — combined with running under EU law, from a company based in Prague — is often closer to what the review is actually trying to establish than a certificate covering infrastructure that isn't where the sensitive workload lives anyway.

Bring the hardware you already have

Enroll a server directly or connect a cloud account — both land in the same inventory the moment they connect, with no migration and no forced adoption. The free plan covers 1 user, 1 organisation, and 5 managed resources with no card required, and paid organisation plans start at EUR 299/month (see [pricing](/pricing/)) with a 14-day full-featured trial that needs no credit card either.

Start free trialTalk to us