Skip to content

Your clients' AI code. Sovereign, isolated, under your brand.

endless guard runs code generated by AI agents hardware-isolated on German servers – with the compliance evidence your clients demand for NIS2 and GDPR. White-label included for your agency.

local-env ~ bash
$claude code deploy --target client-crm
> Initiating secure transfer...
> Establishing MCP connection... [OK]
> Provisioning MicroVM... [OK]
> Isolating environment... [SECURE]
$
Hosted in Germany
GDPR Compliant
Software made in Germany
For Agencies

Your clients are paying for sovereignty. Now you can deliver it.

"Does this run on German servers?", "What about GDPR?", "Who's liable if something goes wrong?" – your clients are asking this more and more, and with US hosting providers you don't have a good answer. endless guard gives you the answer as your own, branded offering: a question that used to cost you deals becomes a premium feature you can charge for.

A New Revenue Stream

Sell "sovereign, compliant hosting" as your own service, with your margin on top. You set the end-customer price; we stay in the background.

Win Deals You'd Otherwise Lose

Regulated clients, public sector, mid-sized companies subject to NIS2: for them, sovereignty isn't a nice-to-have, it's a procurement criterion. This is exactly where you make the difference.

Your Brand, Not Ours

Branded end-customer dashboard, your login page, your domain. Your clients see your agency as the sovereign operator. endless guard stays invisible.

AI writes the code. Who's in control of what it produces?

Chances are your agency is already deploying code an AI agent wrote: a massive speed advantage, and an underestimated risk. Without controlled, isolated execution, every deployment becomes a liability question.

Hours of Manual Review

To minimize risks from dependencies and runtime behavior, every environment today has to be hardened and secured by hand, eating up exactly the speed advantage you deployed AI for in the first place.

Shared Kernel, Shared Risk

Conventional Docker containers share the host server's kernel. In the worst case, faulty or compromised AI code can break out and access the server or other projects' data.

Regulatory Pressure

NIS2 (already in force across the EU, with personal liability for managing directors), the EU AI Act, and the Cyber Resilience Act all require verifiable proof of software supply chain security. Standard pipelines don't provide it.

An answer for every risk.

endless guard addresses every risk above with a concrete technical measure: automated, with zero extra engineering effort, fully hosted on our own infrastructure in Germany.

Seconds, Not Hours

Every deployment lands automatically in a hardened, isolated environment, with no need to set up infrastructure and security measures by hand each time. The costly infrastructure and hardening step simply goes away.

Its Own Kernel, Per Guard

Every Guard runs its own guest kernel in a dedicated MicroVM (Kata Containers): hardware-level isolation, the same approach global hyperscalers use for untrusted code. Even a breakout from the application itself stays contained within its own isolated environment, separate from the host and from other projects.

Provable Compliance

Automatic, tamper-proof access logs and complete audit trails at the platform level deliver exactly the verifiable proof that NIS2, the EU AI Act, and the Cyber Resilience Act require from your software supply chain.

Timeline

We launch the endless guard platform as soon as we have our 5 Founding Partners on board. The deadline for that is December 31, 2026. If we miss the deadline, we guarantee a full refund of all amounts paid.

Start

+1Q

+2Q

Basic Features
Basic Plan

Advanced Pro Features
Pro Plan

Enterprise Features
Enterprise Plan

The Full Feature Set.

Beyond pure risk mitigation, every Guard comes with the tools you and your clients need for production use – from a central agency dashboard to branded client logins.

All Guards in One Place

A central, multi-tenant agency dashboard for provisioning, access rights, and system status, with full visibility into every active client project.

Branded Client Dashboard

Every Guard gets a streamlined white-label view in your branding that your clients manage themselves, including their own user management. You never have to set up access by hand.

Professional Login From Day One

Google, Microsoft, and Apple SSO, classic email/password, 2FA or passkeys, plus white-label login pages with your logo. We deliberately skip error-prone magic links.

Instantly Live, Automatically Encrypted

Every deployment gets a subdomain instantly. Custom domains connect with an automatic SSL certificate (Let's Encrypt), with no manual configuration required.

Pricing

Only 5 Spots Worldwide

Basic

€149 / month
€74.50* / month
saves €1,788 net over 24 months

24 months of 50% discount for our Founding Partners

5 Guard units included
A Guard is an isolated runtime environment in its own MicroVM. One Guard unit comprises 2 vCPU, 2 GB RAM, and 20 GB of local NVMe storage. Guards combine freely: from 1 unit (S) up to 4 units (L) per Guard. Fully hosted in ISO 27001-certified data centers in Germany. Additional units can be added anytime at €29.80 €14.90 / month.
Standard Plan

Pro

€499 / month
20 Guard units included
A Guard is an isolated runtime environment in its own MicroVM. One Guard unit comprises 2 vCPU, 2 GB RAM, and 20 GB of local NVMe storage. Guards combine freely: from 1 unit (S) up to 4 units (L) per Guard. Fully hosted in ISO 27001-certified data centers in Germany. Additional units can be added anytime at €24.95 / month.

Larger quotas and advanced Pro features for growing teams.

On Request

Enterprise

Custom
Custom quota on dedicated hardware
A Guard is an isolated runtime environment in its own MicroVM. On the Enterprise plan, your Guard unit quota is tailored individually to your needs and provisioned on dedicated hardware — which is also where Guards larger than 4 units are available. Fully hosted in ISO 27001-certified data centers in Germany.

Tailored infrastructure and dedicated support for large organizations.

* plus 19% VAT. The Founding Partner price applies for 24 months from platform launch; after that, regular pricing applies (Basic €149 / Pro €499). Persistent volumes for data that must survive a redeployment are available as an add-on at €0.25 net per GB per month, in 10 GB increments.

3 of 5 Founding Partner spots still available2/5
Limited Access

Founding Partner

Your first month as a Founding Partner

€74.50net · plus 19% VAT
5 Guard units included
Freely combinable across any number of Guards. One unit = 2 vCPU, 2 GB RAM, 20 GB of local NVMe storage. Fully hosted in Germany.
50% off for 24 months
No separate deposit. From month 2 onward, automatically €74.50 / month. The Founding Partner price applies until 24 months after platform launch, then €149 / month.
Cancel monthly
Cancel anytime, effective at the end of the month, earliest at the end of the first month after platform launch.
100% risk-free reservation
If the exclusive pool of 5 Founding Partner spots isn't fully claimed by December 31, 2026, we reserve the right to postpone the pilot phase. In that case, your payment will be automatically and fully refunded via Mollie on January 1, 2027.
You'll be redirected to Mollie's secure credit card checkout.

Secure payment via Mollie (EU-regulated). By submitting, you agree to our Terms (available in German; the German version is legally binding).

Frequently Asked Questions

How secure is my data inside a Guard?
Every Guard runs in its own MicroVM (Kata Containers) with its own guest kernel via hardware virtualization (KVM). That is the strongest practical isolation level for untrusted code, the same approach used by global hyperscalers. Every Guard is separated from other projects and from the host kernel, and every access is logged. Your data stays exclusively in Germany.
Does endless guard also review the content of my code?
No, and that's by design. endless guard doesn't evaluate your code's business logic or functionality. What we secure is the infrastructure, data flows, and the runtime environment. Because every deployment runs hardware-isolated, even unexpected code behavior stays contained within its own Guard and can't spread to the host or other projects.
Can I run multiple projects at the same time?
Yes. Every project gets its own isolated Guard with a dedicated MicroVM. The Basic plan includes 5 Guard units, which you distribute freely across Guards — five small Guards with one unit each, for example, or two medium ones plus a small one. Additional units can be added anytime at €29.80 €14.90 / month.
What is a Guard unit?
The Guard unit is our resource and billing size. One Guard unit comprises 2 vCPU, 2 GB RAM, and 20 GB of local NVMe storage. A Guard is always exactly one MicroVM, and depending on its size it consumes a fixed number of units from your quota: S with 2 vCPU / 2 GB RAM / 20 GB (1 unit), M with 4 vCPU / 4 GB RAM / 40 GB (2 units), L with 8 vCPU / 8 GB RAM / 80 GB (4 units). Only the sum of units is capped, not the number of Guards: with 5 units you can run five S Guards, two M Guards plus one S Guard, or one L Guard plus one S Guard. Guards larger than 4 units are provisioned on dedicated hardware under the Enterprise plan. vCPU describes a burst share on shared physical cores and is capped per Guard so that individual workloads — build processes, for example — cannot degrade the performance of other Guards. RAM and local storage, by contrast, are firmly allocated.
Is my data preserved across a restart?
You decide that deliberately, through where the data lives. A unit's local NVMe storage is meant for code, runtime, dependencies, and caches, and it is not replicated: after a restart or a node failure, we automatically restore your Guard from its last deployment image. Anything that has to survive a redeployment — databases, uploads, generated files — belongs on a persistent volume. That is replicated storage, available as an add-on at €0.25 net per GB per month in 10 GB increments. This way you pay for replicated storage only for the data that actually needs it, not for every dependency directory.
Does endless guard support NIS2, EU AI Act, and GDPR requirements?
endless guard automatically logs tamper-proof access logs and complete audit trails at the platform level. This evidence forms the compliance layer you need for your own documentation and your clients': for GDPR and NIS2, and as the technical foundation for further requirements like the EU AI Act. Responsibility for your application's substantive compliance stays with you; we provide the provable infrastructure underneath it.
Which AI models are supported?
endless guard is primarily optimized for local workflows like Claude Code. That said, you can deploy any containerized AI application that communicates over standard interfaces like MCP or REST.
How does deployment via MCP work?
Your local agent connects directly to our API via the Model Context Protocol (MCP). A single command is enough to transfer your code, cryptographically signed, into a new, isolated MicroVM.
Where are the servers located, and is hosting included?
All Guards run in ISO 27001-certified data centers in Germany. One Guard unit comprises 2 vCPU, 2 GB RAM, and 20 GB of local NVMe storage. Depending on its size, a Guard uses 1 to 4 units. Hosting and maintenance are fully included in the price, so you don't need your own server. We guarantee strict GDPR compliance and digital sovereignty.
What happens if the 5 Founding Partner spots aren't filled?
If the goal isn't reached by December 31, 2026, the project will be discontinued and all payments will be automatically and fully refunded via Mollie on January 1, 2027.

About Us

Sovereign Infrastructure, Built for Agencies

endless guard was founded with a clear vision: to give AI and digital agencies the infrastructure to run their clients' code sovereignly, in isolation, and with provable compliance, and to turn it into their own branded offering. To us, digital sovereignty isn't a compromise but a competitive advantage you pass on to your clients.

Behind endless guard is endless webservices GmbH from Bremen. We are not starting from scratch: we have been building and running two SaaS platforms in production for years:

The platform behind Pirtek's hose management, with around 400 active users across six European countries.

docustrysince 2023

Compliance platform for inspection-critical assets, used by inspection service providers for nearly 200 clients.

Both solutions are built for service providers working on behalf of their clients. That is exactly the setup agencies operate in.

Stay in the Loop

Not ready to become a Founding Partner yet, but want to stay informed about our progress? Sign up for our newsletter.

Contact

Have questions? We'd love to hear from you.