The questions that decide fit.
Features in this category have converged: everything investigates, everything summarizes, everything chats. Posture hasn’t converged. Ask any vendor, including us, these ten questions, and the category sorts itself.
The frame
Ten questions, in four themes.
Our own answers, one line each, we answer our own questionnaire first, in public. Every answer is checkable on the pages this site links to.
PLACEMENT
| The question | Our answer |
|---|---|
| Where does it run, vendor cloud, your cloud account, or your cluster? | In your cluster, by Helm. No Infraware control plane exists to run elsewhere. |
| Where does your operational data go, and who can reach it besides you? | Nowhere we chose for you. Only your configured LLM traffic leaves, or nothing, with the model served in-cluster. |
| Who owns the model, can you bring your key, and can you run it fully local? | You do: Anthropic, OpenRouter, or Mistral on your key, or vLLM serving open-weight models, fully local. |
BOUNDARIES
| The question | Our answer |
|---|---|
| What can it do without a human, and is that a policy or an architecture? | Read-only investigation, and it's architecture: there is no write path to flip on. |
| What exactly can it execute? Is the command surface finite and inspectable, or "what the model decides"? | A fixed allowlist of read-only command prefixes, and a quote-aware parser that rejects anything it can't fully parse. |
| What happens when the model is wrong, the parser is confused, or a component dies, does the system do less, or guess? | Less, always: parse errors reject, no report means no action, a downed component pauses investigation. |
ACCOUNTABILITY
| The question | Our answer |
|---|---|
| Under whose identity does an action execute, a shared service account, or an identity derived from the human who approved it? | A Kubernetes Job under a ServiceAccount mapped from the approver. Read and write principals are separate. |
| For any given change, can the vendor answer: who approved it, on what evidence, and what ran? | Yes, per command: one audit entry names the approver, the resolved principal, the command, and the outcome. |
| What record exists afterwards, where does it live, and can you hand it to an auditor or insurer without the vendor’s help? | One structured entry per approved execution, in your own log storage. Query it yourself; nothing routes through us. |
PROOF
| The question | Our answer |
|---|---|
| Can you verify the claims in your own cluster before you pay, and will the vendor print a price? | Yes: install in an afternoon, run the reference failure suite yourself. Pilot: scoped on the first call, one number, and it doesn’t change after. |
Verify any answer above: the security page · how it works · pricing.
The autonomy question
Questions 4 and 7–9 together are the one our frame answers: when it acts on its own, who granted that, and where is the grant recorded? Every product in this category acts unattended somewhere; the sorting fact is whether the unattended action runs on a named human’s grant or on a vendor default.
Our own answer, in both halves: reads run autonomously under a read-only policy you set; standing grants for writes are rung 3 of the autonomy ladder Shipped : approve the same fix often enough and it becomes policy for that exact context, revocable in one click.
See the whole autonomy ladderQuestion 10 is the quiet knife. The category norm is quote forms and hosted sandboxes; we scope the pilot on one call, and install in your cluster in an afternoon.
Two comparisons
Where the posture actually divides.
Against autonomy-first self-hosted agents
Last verified 2026-07-31 · See something outdated or unfair? security@infraware.dev, we correct comparison pages within a week.