SOVEREIGN RUNTIME CONFIGURATION / PUBLIC PREVIEW

Your accounts.Your signed runtime.Any cloud.

Connect provider accounts you already pay for. Select models, tools, policies, and placement. After approval, DSCO builds and signs a hardened, customer-specific runtime artifact. Its RuntimeSpec is the reproducible contract.

01 No keys collected here02 Local remains a first-class target
RUNTIME / 00-7A● SPEC LIVE
ACCOUNT CONNECTION REFERENCES03 ELIGIBLE
canonicalize
contractRuntimeSpecartifactruntime.bindigestsha256:78b4…
place
DSCO CLOUDMANAGED
YOUR CLOUDPORTABLE
LOCAL EDGESOVEREIGN
✓ CREDENTIAL MATERIAL EXCLUDED✓ CUSTOMER-SPECIFIC BUILD✓ SIGNATURE REQUIRED
ONE APPROVED BUILDTHREE TARGETS
USE EXISTING PROVIDER ACCOUNTSNON-SECRET CONNECTION REFERENCESHARDENED SIGNED ARTIFACTSMANAGED · CUSTOMER CLOUD · LOCALUSE EXISTING PROVIDER ACCOUNTS
THE PRODUCT SHIFT

Cloud is a target.
Not your dependency.

DSCO Cloud is the managed front door to the same governed runtime that can execute in customer infrastructure or on a local machine. The deliverable is a customer-specific signed runtime artifact; the RuntimeSpec is its reproducible contract.

A Bring provider relationships you already own.B Keep credentials outside prompts and specs.C Verify the artifact against the approved contract.

01 / RUNTIME CONFIGURATOR

Configure the runtime DSCO will build for you.

Choose connection references, routes, tools, policy, and placement. The RuntimeSpec is deterministic; account approval authorizes a customer-specific hardened build.

No provider credentials enter this page or the RuntimeSpec.

Connections are completed in your DSCO account and represented here only by non-secret references such as account://openai.

Open connection center
01 Runtime identity

Use 1–64 lowercase letters, numbers, dots, underscores, or hyphens; begin with a letter or number.

02 Provider accounts

Select eligible routes. Mark one as primary.

Account connection required
Account connection required
Account connection required
Account connection required
Discovered by the local runtime
03 Routing
04 Tools

Only capabilities with compiled, fail-closed cloud enforcement are offered here.

05 Governance

Read and build freely; approve external writes and sensitive actions.

06 Deployment target

02 / CONTROL PATH

From paid account to signed runtime.

Connection, configuration, approval, build/sign, and execution remain explicit boundaries.

01

CONNECT

Reference accounts you already use.

Complete provider connection in your DSCO account. The runtime receives a scoped reference—not a credential pasted into a prompt, page, or spec.
02

CONFIGURE

Select the system, not just a model.

Declare eligible providers, primary and fallback routes, tools, budgets, approval points, and evidence requirements together.
03

APPROVE

Approve the exact contract.

Review the canonical RuntimeSpec, its connection references, policy, placement, and content digest through the customer account boundary.
04

BUILD + SIGN

Produce your hardened runtime.

DSCO builds a customer-specific binary or deployable artifact from the approved spec, then signs the artifact and its manifest together.
05

RUN

Place it where authority belongs.

Run the signed artifact on DSCO Cloud, in customer-owned cloud infrastructure, or locally at the edge.

03 / PLACEMENT

Choose where the runtime answers to you.

Placement changes infrastructure ownership, not the declared providers, tools, policies, or evidence contract.

01 / MANAGED

DSCO Cloud

Approve the spec, then build and sign an isolated runtime artifact for managed placement.

Open account
02 / PORTABLE

Your cloud

Build a signed deployable artifact with the approved RuntimeSpec as its contract.

Generate spec
03 / SOVEREIGN

Local edge

Build a signed native binary near repositories, local models, and private state.

Start local
BOUNDARYDSCO CLOUDYOUR CLOUDLOCAL EDGE
CONTROLManaged account planeCustomer-owned planeLocal process
EXECUTIONIsolated cloud runtimeCustomer cloud runtimeNative DSCO runtime
PROVIDER AUTHAccount referencesInjected by customerLocal or account refs
EVIDENCEChronicle streamExportable ChronicleLocal Chronicle
PORTABILITYRuntimeSpec exportRuntimeSpec importRuntimeSpec file

04 / GOVERNANCE

Autonomy with an inspectable constitution.

Policy ships with the runtime. It does not disappear when execution moves from local to managed infrastructure.

CAP-01

Capability scopes

Declare filesystem, shell, network, tool, and external-action boundaries before execution.

APR-02

Approval gates

Require human approval at the transitions that can mutate state or spend authority.

BGT-03

Budget envelopes

Bound cost and fan-out per run instead of discovering spend after the trace closes.

PRV-04

Provenance by default

Record routing, tool calls, policy decisions, outputs, and artifacts in one evidence chain.

POLICYEXECUTIONEVIDENCEbound by the same RuntimeSpec

05 / LOCAL EDGE

The cloud relaunch keeps the machine in the system.

Install the native runtime for repository-local work, on-device models, and execution that should never leave the edge. Add account references only when a task needs a remote provider or managed surface.

NATIVE RUNTIMELOCAL MODELSCHRONICLEMIT
DSCO / LOCAL● READY
$ npm install -g @distributed.systems/dsco$ dsco login$ dsco "run this RuntimeSpec locally"

CONFIGURE ONCE / PLACE DELIBERATELY

Build the runtime you can verify and move.

Configure RuntimeSpec Continue to account
Account setup begins here; private connections, signing, and managed deployment continue in the secure tools plane.