The platform
Nexocloud organises a 60-service sovereign platform into the AWS-style categories you already think in. Each category below maps to real backend services with real operation counts; open one for its services, method+path endpoint catalog, a worked example and its architecture placement.
Cloud categories
Each card links to a deep-dive: the services in the category with real op counts, the real method+path endpoints from the openapi contracts, a worked example, and where it sits in the architecture.
Run anything — a git repo, a backend, a fleet of demo stacks — on governed compute.
The compute plane of the sovereign cloud: push code and get a routable, autoscaled, admission-gated app; stand up a full backend (auth, data, functions) declaratively; or spin ephemeral environments with cost guardrails and TTL teardown. One tenancy model, one audit chain, no bolt-ons.
Build, sign, scan and ship artifacts through a governed delivery spine.
The delivery plane: a policy-driven build factory, a multi-target app/mobile build-and-release system, a quality/test grid that gates releases, and a signing container registry where nothing is admitted without a signature, SBOM and a clean scan. Evidence is a byproduct of shipping.
S3-compatible object storage and 3-2-1 backup on a data plane you own.
A fully S3-compatible object store — buckets, versioning, lifecycle, multipart, presigned URLs and native S3 verbs — plus a backup and disaster-recovery plane with 3-2-1 audit, drill cadence, recovery ladders and DR topology. Intra-edge egress is zero-rated: no bandwidth ransom on the way out.
Relational, document, vector and analytics data — one governed database plane.
ADR-0056 makes the DBaaS the only database plane on the platform: every engine is a claim with placement, leases, CDC, point-in-time restore and key rotation. Prism turns product events into contract-checked metrics; Mediation rates and reconciles high-volume usage records. No shadow databases, no unmanaged data.
VPCs, a sovereign mesh, authoritative DNS, edge compute and a PoP fabric you run.
The network plane: VPCs and a zero-knowledge WireGuard mesh with SASE/ZTNA policy, DNSSEC-signed authoritative DNS with health-checked answers, an edge-compute and CDN plane with WAF and cache control, and a CloudPoP fabric where you register the points-of-presence and BGP sessions yourself. The data plane is yours end to end.
Identity, fine-grained authz, secret custody, detection & response, and compliance evidence.
The trust plane: OIDC identity and multi-tenant users, relationship-based authorization with replayable decisions, a Vault secret and Transit-signing engine, a SecOps detection-and-response platform, GRC controls and findings, plus KYC and privacy (consent, DSAR, erasure). Governance is structural — every service inherits it, none re-implements it.
Metrics, logs, traces, SLOs, incidents, a live CMDB and release gating.
The operations plane: VRQGO for metrics, logs, traces, probes and burn-rate SLOs; OpsTrac for incident command, on-call rotations, paging and postmortems; a live CMDB with blast-radius and dependency graphs; and Droplet, the release-candidate gate that judges what is safe to ship.
Durable workflows, an event bus, connectors, realtime channels, rules and schedules.
The integration plane: Temporal durable workflows with signals and resets, an event bus with schemas and consumer groups, an integration hub with connectors, DLQ replay and canonical events, realtime presence channels, a versioned rules engine with replayable receipts, and exactly-once scheduling.
Model serving, RAG, guardrails, an MLOps feature store and a federated MCP tool gateway.
The intelligence plane: a model-serving broker with budgets, guardrails, embeddings, knowledge bases and canary promotion; an MLOps plane with a feature store, drift detection, skew checks and serve-guards; and a federated MCP gateway that catalogs tools across nodes so agents call governed, discoverable tools.
A double-entry payments core, metered billing, wallets and a provider marketplace.
The commerce plane: PayCore runs a double-entry ledger with payment instructions, settlement, payouts, rail routing and SCA; Billing meters usage, finalises invoices, runs dunning and tax; Wallets holds balances with holds and captures; and the Provider Marketplace onboards providers with reservations, settlements and reconciliations.
Carrier-grade voice routing, messaging, notifications, fraud control and media.
The communications plane: least-cost voice routing with SBC, SIP, STIR/SHAKEN and WebRTC; value-added services (voice apps, USSD, ACD, subscriptions); multi-channel notifications with SMSC and OTT; telecom fraud and revenue-assurance controls; and a media plane for transcode, packaging and DRM-gated playback. This category cross-links to the dedicated CPaaS portal.
An internal developer portal, the API gateway, docs, value-ops and FinOps.
The developer plane: a DevPortal with golden paths, scorecards and a service catalog; the API gateway that admits and routes external traffic with entitlements; a docs plane that keeps API references fresh and drift-checked; ValueOps for product bets, OKRs and prioritization; and FinOps for budgets, cost anomalies, allocation and unit economics.
One platform underneath
A category is just a lens onto the same governed platform. Compute composes storage, databases, security and observability; payments leans on identity and the audit chain; every category inherits the same tenancy (ADR-0019), the same Vault-signed audit (ADR-0014) and the same owned data plane (ADR-0056). That is what a hyperscaler's two-hundred-service sprawl cannot offer: one plane, one bill, one way out.
Nexocloud is the StratoGroup sovereign platform: 60 governed services exposing 1,420 operations, organised here as 12 cloud categories.