Product overviewMake critical-system recovery testable, evidenced and board-defensible.
ContinueOps automates DR runbook execution with tamper-evident evidence chains, human-on-the-loop approvals and a zero-egress architecture - without standing up an internal platform team.
Deployment options, the live Windows product demo, and our security model - in one place.
ContinueOps already runs in regulated production environments. These are the customers whose runbooks fire today, whose evidence packs go to auditors, and whose teams will join a reference call on request.
SAI Group
Production runbooks, weekly DR validation, full evidence chain.
Message Matrix
Operational runbooks across AWS workloads with HOL approvals.
Syndic8
Multi-region failover rehearsals + auditor-ready evidence packs.
"We replaced a quarterly 2-day fire-drill with a one-click rehearsal we can defend to our auditors. The evidence pack is the bit that sold it internally."
For regulated environments and strict data-residency requirements, the self-hosted appliance runs entirely inside your VPC with no inbound ports and no data egress. A managed SaaS option is also available.
Read the full deployment guide
Self-hosted appliance.
A signed virtual appliance you deploy inside your own VPC. Outbound-only mTLS to the control plane. Runbook outputs, captured variables and credentials never leave your environment.
Ships in your preferred platform.
- OVA / OVFVMware vSphere, ESXi 7+
- Hyper-V VHDXWindows Server 2019/2022
- QCOW2 / KVMProxmox, OpenStack, libvirt
- AMI / GCEAWS · Azure · GCP marketplace
- Helm chartKubernetes 1.27+ · OpenShift
- Docker ComposeSingle-host air-gapped lab
No credential storage on the agent, runtime secret injection and data that does not leave the customer environment. That is the default with no additional cost.
No credential storage on the agent
Single stripped Rust binary. Cloud credentials are never persisted. mTLS client cert lives in the OS keystore, never on disk in plaintext.
Secrets injected at runtime
Vault, AWS Secrets Manager, Azure Key Vault, GCP Secret Manager or CyberArk. Per-step fetch, zeroised on completion.
Data does not leave your environment
Outbound-only mTLS to the control plane. Runbook outputs and captured vars stay inside your VPC.
Local LLM option
Ships with our proprietary self-hosted model, reasoning runs on your hardware.
RFC 3161 trusted timestamps
Every runbook step, evidence artefact and approval is sealed with an RFC 3161 timestamp from a trusted TSA. Tamper-evident, auditor-defensible, and verifiable years later - no need to trust ContinueOps' clock or storage.
Capabilities that are toggled on per tenant via feature flags - enabled only where they fit your operating model and compliance posture.
Inter-user messaging
Direct, tenant-scoped conversations between members of the same tenant - useful for runbook hand-offs, incident chatter and approval context. Off by default; enabled per tenant via a feature flag, with full RLS isolation, attachment storage and audit trail.
Per-tenant feature flags
Every optional capability - messaging, compliance dashboards, integrations - is gated by a per-tenant feature flag. Operators decide what's on for whom, with no code changes and no cross-tenant leakage.
- 01Week 1
Kick-off + agent enrolment
License issued, agent deployed in your VPC, mTLS handshake confirmed. Zero inbound ports.
- 02Week 2
First runbook live
We co-author your highest-value DR runbook. First successful tamper-evident run logged.
- 03Week 3
HOL + evidence wired
Human-on-the-loop approvals into your channel of choice. Evidence pack auto-generated.
- 04Week 4
Hand-over + sign-off
Top-5 critical systems covered. RFC 3161 timestamped certificates ready for your auditor.
See ContinueOps in your environment.
- 01
30-minute working session - walk through the agent architecture and answer credential / data-residency questions live.
- 02
Reference call with one of SAI Group (Retail), Message Matrix (Media / TelCo) or Syndic8 (E-commerce) - your choice of sector and framework.
- 03
Pilot kick-off the following week - fixed-fee setup, first runbook live in week 2.
Typical pilot time-to-value: 4 weeks