The architecture

Clear places for data, compute, and control.

Geyser separates the customer’s working environment from the shared services that operate the platform.

Explore an example setup
Your workspace
Data home

Geyser-managed Customer Cell

Agent computers

Hosted Agent computers

Processing

Your approved model & app services

Geyser service operations

Identity, directory, billing, routing, releases, and health.

Geyser operates the data home and Agent computers. You choose the connections and processing routes.

01

The Customer Cell is the data home.

A Customer Cell holds the authoritative customer content and controls: shared work, Rooms, memory, secrets, policy, and audit records. A managed Cell is operated by Geyser; a supported Host or enterprise Cell can put that custody in the customer’s environment.

Agent computers also hold working files, browser state, and local working context. Backups, exports, and connected services have their own copies or processing responsibilities. “Authoritative home” identifies custody; it does not mean there are no other working copies.

02

Agent computers are placed independently.

Agent compute can run in managed isolated sandboxes, on supported Mac or Linux Hosts, or across both. Choosing a Host for compute does not automatically relocate the Cell.

This separation lets a team choose who operates its data home and who supplies its Agent computers. Moving between supported placements is a deliberate operation with its own routing and recovery behavior.

Compare deployments
03

The path is part of the boundary.

Direct Aquifer paths form a customer-scoped private network and are end-to-end encrypted between authenticated peers. Managed deployments and other supported placements use authenticated encrypted outbound tunnels.

The endpoints and custody differ between those paths. Model requests, speech, and connected app calls follow their configured processing routes. Explicitly approved shared provider bridges can process content in transit; a content-free administrative view does not remove that processing path.

04

Shared operations stay separate from customer work.

Geyser Global keeps the operational information needed for identity, directory, billing, routing, releases, health, and Cell assignments. Customer content remains authoritative in the Cell; a lost Cell route does not silently make Global its new data home.

Content-bearing support access uses a named, scoped, expiring grant approved by the customer owner and recorded in the audit trail. Access is tied to a purpose and a customer boundary.

05

A tighter configuration for a tighter boundary.

Private Cell Strict applies default-deny egress and customer-controlled inference routes. It disables the shared content relay, shared provider bridge, and content federation while retaining bounded central operational functions.

The configuration is checked against its supported deployment requirements. Strict-private operation also limits external meeting and application paths. It is a deployment posture, not a claim of an independent compliance certification.

Discuss a private deployment
Good questions

A few useful answers

What about cross-organization Rooms?
Explicit membership and policy govern shared work between customer boundaries. Strict-private posture disables content federation.
Does encryption mean Geyser cannot process any content?
Encryption protects a defined path between endpoints. Managed processing, authorized support, and approved provider bridges have their own access and processing boundaries. Review the selected deployment and routes.
Make a start

Start with one agent and a job worth doing.

Create a workspace, bring your team, and see what you can get done.