Product
Sovereign mode.
Sovereign mode is the default. There is no other mode. Every token, every prompt,
every completion stays inside your VPC, on your GPU. Kan only sees metering events.
What stays on your side.
- Inference traffic. Your end users connect directly to your fleet. APISIX terminates TLS, Hux dispatches to vLLM, the completion streams back. The data path never touches Kan.
- Model weights. Hux pulls models from Hugging Face or your private registry; Kan only sees the model name and slug, never the bytes.
- API keys. Plaintext keys are shown to you ONCE at creation time, then hashed with HMAC+SHA256 server-side. Hux receives only the hash + prefix in its keyauth-map sync, and stores them in fleet-local Redis. The plaintext never roundtrips through Kan again.
- Prompts & outputs. APISIX strips Authorization and apikey headers before forwarding to vLLM (no leak to your model server logs). And nothing about the request body ever crosses to Kan.
What we get.
Just enough to bill, alert, and dashboard:
- Per-request: timestamp, model name, status code, total/upstream/TTFT latency, input/output token counts, hashed client IP, error code.
- Per-node: heartbeat liveness, applied config revision, agent version, GPU/RAM/CPU stats.
- Per-fleet: aggregated counters for the dashboard.
Why not air-gapped?
Air-gapped means the agent never talks to Kan at all — useful for classified networks. Sovereign mode is the practical middle ground: outbound HTTPS to app.huxkan.com for config and metering, but no inbound traffic from Kan and no payload data on the wire. If you need full air-gap, contact us.
Try sovereign mode →