DXMachine is a workflow execution platform. AI agents participate in completing regulated compliance workflows — and the attestation architecture is what makes those agents legally and regulatorily acceptable. The full architecture runs on bare metal. That is not where every organization starts. Here is the honest path from where you are today.
No organization is required to start on bare metal. The architecture is designed to deliver value at every tier — with honest documentation of what each tier can and cannot attest to.
Every row below reflects the real architectural difference between tiers. The expectation management column is not fine print — it is the most important column on this page.
| Dimension | Legacy · Tier 1 Existing Infra |
Hybrid · Tier 2 Mixed Deployment |
Full DXMachine · Tier 3 Bare Metal Agent Host |
|---|---|---|---|
| Execution Environment | Your existing cloud, Azure, K8s, or VMDXMachine workflow engine runs on general-purpose infrastructure you already control. | DXMachine Agent Host alongside existing infraCompliance-critical workflows run on the Agent Host. Other systems continue unchanged. | Purpose-built Yocto Linux imageNo general-purpose OS. No shell. No SSH. No installer. Absence is structural, not advisory. |
| Hardware Attestation | Workflow records onlyAudit trail reflects what DXMachine recorded. No cryptographic proof of execution environment integrity. | Full attestation on DXMachine-managed workflowsTPM 2.0 measured boot on Agent Host workloads. Legacy workloads carry standard records only. | TPM 2.0 measured boot — full chainHardware-backed signing key. Cryptographic record of every component loaded at startup. Examiner-verifiable. |
| AI Agent Trust Model | Advisory policyAgent capabilities governed by application-layer controls. Enforceable within DXMachine but not at the OS layer. | Capability-gated on Agent Host workloadsSigned JSON capability manifests for workflows running on the Agent Host. Standard controls elsewhere. | Structural enforcement — absence is physicalA capability that does not exist cannot be exploited. No shell means no shell. Not a policy. Not a configuration. |
| Regulatory Defensibility | Documented workflow recordsAudit-ready artifacts for DXMachine-managed work. Examiner will ask about execution environment. Honest answer: general-purpose infrastructure. | Defensible for Agent Host workflowsHardware attestation available for compliance-critical workflows. Examiner can verify execution environment for those workloads. | Examiner-ready, cryptographically verifiableEvery execution record signed by a TPM-resident key. Examiner can verify not just the log but the system state that produced it. |
| ITAR Suitability | Not recommendedCloud or shared infrastructure creates potential unauthorized export exposure for ITAR-controlled data. Legal review required before use. | Suitable for ITAR workflows on Agent HostITAR-controlled workflows routed exclusively through on-premises Agent Host. Segregation must be enforced by deployment architecture. | Designed for ITAR environmentsCompute runs on hardware you control, in a facility you control. No foreign cloud exposure. Sovereignty is structural. |
| Pricing Model | Standard token exchange spreadDomain-specific markup on AI compute. Specific mechanics co-developed with design partners. | Tiered — Agent Host workflows at full rate, legacy at standard ratePricing reflects value delivered per workflow tier. Hybrid deployments priced by workload type. | Full value-based pricingToken exchange spread differentiated by workflow domain. CMMC Level 3 commands different margin than a change advisory workflow. The architecture captures that difference. |
| Migration Complexity |
Low
Deploy on existing infrastructure. Standard integration. Fastest path to first workflow running.
|
Medium
Agent Host provisioning alongside existing systems. Workflow routing decisions required. Weeks to initial deployment.
|
Greenfield or parallel run
New workflows start here. Existing workflows transition over a defined period. Highest setup investment, highest long-term return.
|
| Expectation Management | Get you in the door. Prove the workflow value.A regulator who asks about your AI execution environment will receive an honest answer: general-purpose infrastructure. This is the evaluation tier, not the production compliance tier for high-stakes examination workflows. | The realistic path for most organizations.Most enterprise customers start here. Compliance-critical workflows get full attestation. Legacy workflows transition on their own timeline. This is how regulated organizations actually adopt new infrastructure. | The architecture delivering its full thesis.This is what DXMachine was designed for. Not every organization starts here. Every organization with serious compliance obligations should plan to get here. |
The bare metal requirement is the most unusual claim on this site. It deserves a direct explanation rather than a marketing paragraph.
"The question is not whether Azure is trustworthy. The question is whether the examiner will accept 'we used Azure' as a sufficient answer. For some workflows, yes. For others, no. We will tell you which is which."
We will also not tell you that the transition from Tier 1 to Tier 3 is trivial. It requires infrastructure decisions, procurement cycles, and organizational change. The hybrid path exists because we understand that regulated organizations cannot rebuild their infrastructure in a quarter.
What we will tell you is that the workflow value — the card model, the audit thread, the AI agent participation in completing compliance work — is real at every tier. You are not buying a governance layer. You are replacing the specific compliance workflows your team is managing in spreadsheets and disconnected tools, with a platform that produces examiner-ready artifacts as a native output of normal work.
The tier determines the strength of the attestation. The workflow value is present regardless of tier.
No SDRs. No drip campaigns. A direct conversation about your compliance environment, your infrastructure constraints, and which tier makes sense for where you are today.