The operating layer
What we would run, and what stays yours.
CloudVault is pre-launch. This is the operating model being built, not a description of
something already running — so every capability below is marked confirmed or planned.
Where the line sits
Pick a responsibility. See both sides.
White-label only works when ownership is unambiguous. This is the provisional operating
model — a product control rather than a contract, and a commercial agreement will refine it.
Your agency CloudVault
01 Client relationship See the split
Your agency keeps Owns the commercial and day-to-day client relationship.
CloudVault handles Stays behind your agency. Does not market or upsell to your clients.
02 Application code See the split
Your agency keeps Owns source, dependencies, build configuration, and application defects.
CloudVault handles Does not change code without an approved support request and repository authorization.
03 Deployment See the split
Your agency keeps Supplies a deployable build, a production branch, and release approval.
CloudVault handles Provisions and maintains the supported pipeline once it is implemented.
04 Data and auth See the split
Your agency keeps Owns schema, migrations, authorization logic, and data correctness.
CloudVault handles Maintains the managed database and auth service within confirmed boundaries.
05 Domains and DNS See the split
Your agency keeps Confirms domain authority and authorizes cutovers and client-facing timing.
CloudVault handles Prepares and validates infrastructure records within approved scope.
06 Backups and restores See the split
Your agency keeps Identifies critical data and authorizes restore point, target, and timing.
CloudVault handles Runs only the backup services included in the approved plan.
07 Incidents See the split
Your agency keeps Coordinates client communication and application-level remediation.
CloudVault handles Diagnoses infrastructure-scope incidents and reports facts to you.
08 End-user support See the split
Your agency keeps First-line support for the client and its users.
CloudVault handles Not included by default.
09 Exit and portability See the split
Your agency keeps Coordinates the destination, validates exports, and manages client communication.
CloudVault handles Provides the agreed export and infrastructure handoff after authorization.
Escalation stays simple End client → Agency → CloudVault Exceptions must be explicit, narrow, and documented. A client emergency contact does not become a general support channel, and never becomes a route for us to sell around you.
Hold us to the model.
If this is the operating layer you would want behind your client sites, join the founding-partner list. We would rather hear where it is wrong now than after it is built.
// Pre-launch. Founding partners are onboarded personally, one site at a time.