Skip to main content
    Reign OpsAI substrateAgent runtime operations

    We do not build agents. We run them the way you run everything else.

    Agent runtimes operated in production under controls: sandboxed at the process and network boundary, with runtime image lifecycle, sandbox policy, agent identity, capacity and incident response run by the engineers who answer the pager.

    Delivered as a single-tenant dedicated instance, in infrastructure iTmethods operates or in your own cloud account on AWS or Azure. Both are available today. Air-gapped and sovereign are in development.

    The decision you are actually making

    An agent your team started on a laptop is not in production.

    The gap between a working agent and an operated one is the same gap that has always existed between a working service and an operated one. It is just newer.

    01It needs somewhere specific to run
    A named runtime, an image whose lifecycle somebody owns, and a sandbox policy set before it starts.

    Agents that run wherever a developer happened to start them are the reason nobody can answer what ran last quarter.

    02It needs an identity of its own
    Bound to your provider, distinct from the person who launched it and from every other agent.

    Shared credentials make the record useless at exactly the moment somebody needs it, because everything resolves to one account.

    03It needs a boundary it cannot argue with
    Sandboxed at the process and the network boundary, so what it can reach is a decision rather than an outcome.

    This is the layer that stops an agent's mistake from being an incident, and it is set once rather than per prompt.

    04It needs somebody on the pager
    Capacity, scheduling and incident response, operated rather than watched.

    Agent workloads fail in ways ordinary services do not, and at hours that suit nobody. There is a named engineer and a current runbook.

    What we operate

    The runtimes your engineers have already chosen.

    Orchestrated and sandboxed under one operating model, whichever ones you run. Adding another is a scoping conversation rather than a migration.

    RuntimeHow Reign Ops runs it
    Cursor Self-HostedIsolated environments per agent session, inside your boundary, with model routing through the governed gateway.
    Claude CodeOperated with governed routing and prompt and tool guardrails, with the record written where the work happened.
    LangGraphOrchestrated and sandboxed at the process and network boundary under the same policy as every other runtime.
    Sandboxed runtimesKernel-level sandbox isolation and deny-by-default network policy for the runtimes that support it.
    Your ownAn in-house runtime is operated under the same contract. There is no separate path for something you built.

    The same tools appear in AI-native governed SDLC when a human is at the keyboard rather than an autonomous agent. The boundary between the two pages is human-in-the-loop versus autonomous action, and the governance posture is set accordingly.

    What Reign Ops applies on day one

    Set before the runtime starts, not after.

    Applied at deployment as configuration under version control rather than as settings somebody remembered.

    Provisioning and image lifecycle.

    Runtime images built, patched and rotated on a cadence, rather than pinned to whatever version was current when the agent first worked.

    Sandbox policy and network boundary.

    Deny by default at the network edge, isolation at the process boundary, and no shared execution surface between agents that should not see each other.

    Identity, access and secrets.

    Single sign-on and role-based access bound to your provider, with short-lived credentials rather than long-lived ones held in a runtime.

    Capacity, scaling and the pager.

    Scheduling and capacity operated for you, with a named engineer and a current runbook when something needs a person at an inconvenient hour.

    Attestation status and the standard pack for procurement are released on request under non-disclosure rather than asserted here. Security and trust →

    Where Reign fits

    Reign Ops runs the runtime. Reign governs what the agent does inside it.

    Operating a runtime well bounds what an agent can reach. It does not, on its own, tell anyone what the agent actually did. Reign Gateway sits on the model path and the tool path, and that is where the answer to that question gets written.

    What the record carries
    For each session: the agent identity, the runtime it ran in, and the sandbox policy in force. For each model call and each tool binding: what was asked, what applied, what was allowed and what came back. Written at the moment of execution rather than assembled from logs afterwards.
    The part worth being precise about. This is a record of what an agent did, prepared so a reviewer can follow it. It is not a verdict on whether the agent behaved well, and operating a runtime safely is not a claim that what runs inside it is correct. iTmethods makes no compliance, certification or accreditation claim under any framework. How the boundary works → · Regulatory alignment →
    Shared responsibility

    What we run, what you run.

    Written down before anything is deployed, so the boundary is a document rather than a discovery.

    WhoWhat they hold
    Reign Ops, automatedProvision and operate the runtimes inside your authorization boundary. Build, patch and rotate runtime images. Enforce sandbox policy at the process and network boundary. Bind agent identity to your provider. Operate capacity, scheduling and incident response. Isolate a runtime when something goes wrong.
    Customer authoredWhich agents run and what they are for. What each one is allowed to reach. The data classification that applies. Who may approve a new runtime or a policy exception. Your models, your prompts, your code.
    Operating partner engagementOnboarding runtimes in scoped waves. Standing up the initial sandbox and identity policy with your team. Authoring the first evaluators against your agent surface. The periodic posture review, and the decisions that change the design rather than the configuration.
    Before the scoping call

    The questions that arrive every time.

    Do you build or sell agents?
    No. Reign Ops operates the runtime they execute in. Which agents you run, and what they are for, is your decision and it stays yours. Reign Factory is iTmethods’ own agent and it is a separate motion with its own page.
    Can we bring an agent we wrote ourselves?
    Yes, under the same operating contract. In-house runtimes get no separate path around sandboxing, identity or the record, which is the point of having one contract.
    What happens when an agent misbehaves?
    The sandbox is what bounds the damage, and it is set before the runtime starts. Incident isolation removes the runtime from the estate without hunting for what it was connected to, because identity and tool bindings are already recorded.
    Which deployment shapes can we have?
    A single-tenant dedicated instance, in infrastructure iTmethods operates or in your own cloud account on AWS or Azure. Both are available today and both are single-tenant. Google Cloud is planned for 2027. Air-gapped and sovereign are in development. There is no multi-tenant or shared option at any tier. Deployment options states which is which without softening any of them.
    What does it cost?
    Scoped per engagement. This site publishes no price list and no tiers, because what we would operate for you is the thing being priced and it is different every time. The scoping call is where that gets answered, and it commits you to nothing.
    Linux Foundation, Silver member Agentic AI Foundation, Silver member
    Member and contributor in the open standards behind governed AI. Twenty-one years operating foundational infrastructure inside customer environments.
    Next step

    Tell us what your agents run in today.

    Which runtimes, how they are started, and whether anyone can currently name the identity each one uses. We will come back with what we would take on first and what we would leave alone.