# Enterprise exe


exe.dev is a cloud for your company's agentic software: the agents your
developers build with, and the VMs that software runs on once it's built.
Enterprise is the same platform with limits set by contract,
[hardware dedicated to you](/docs/enterprise-single-tenant) or
[your own](/docs/enterprise-byoc), SSO, support in a shared Slack channel,
and an [uptime SLA](/docs/enterprise-sla). A Business Associate Agreement
(BAA) is available for teams that handle protected health information under
HIPAA.

## Compute

Your team reserves [pools](/docs/pools) of CPU and memory and runs as many
VMs in them as the capacity supports. Each VM is KVM-isolated, with its own
port 80 and its own disk on the server's local NVMe, streamed continuously to
another server in the region so it survives the loss of a machine.
[Standalone VMs](/docs/standalone-vms) give a sandbox capacity of its own,
for agent-written code, CI jobs, and previews.
[The exe Architecture](/docs/architecture) shows how it fits together.

On Enterprise, pool sizes and VM counts are whatever your contract says,
pools run on [single-tenant hardware](/docs/enterprise-single-tenant), VMs
can run nested VMs, and the hosts can be your own
([BYOC](/docs/enterprise-byoc)).

## The network edge

Every VM is on the internet at `https://vmname.exe.xyz/`, with certificates
and TLS handled by the [HTTPS proxy](/docs/proxy), and can serve your own
[domains](/docs/cnames). Sites are private until they are
[shared](/docs/sharing), and [Login with exe](/docs/login-with-exe) tells
your app who is visiting, so internal tools need no auth code of their own.

## Integrations

[Integrations](/docs/integrations) add credentials to a VM's outbound
requests on the network, so secrets never land on the VM where an agent
could read them. With workload identity federation, VMs assume roles in
[AWS](/docs/integrations-aws-wif) and [GCP](/docs/integrations-gcp-wif)
without stored keys, and the [LLM integration](/docs/integrations-llm)
gives them models without provider keys.

## Teams and access

A [team](/docs/teams/overview) shares pools and VMs, with member, admin, and
billing owner roles. Enforce [SSO](/docs/teams/sso) through Google or any
OIDC provider (Okta, Azure AD, and so on), and use
[sharing controls](/docs/teams/sharing-controls) to decide who may expose a
VM beyond the team.

## Agents

[Shelley](/docs/shelley/intro), our coding agent, runs on every VM started
from the default image. It works with exe.dev's models or
[your own keys](/docs/shelley/byok), and you are free to run any other agent
alongside it.

## Automation

Everything is scriptable: over SSH, through the [HTTPS API](/docs/https-api),
and from agents with [MCP](/docs/mcp). Try any command in the
[API/CLI explorer](/api).

## Billing

Pool capacity, standalone VMs, disk, and bandwidth are covered by your
contract instead of metered. `team usage` shows pool capacity as
"Contracted". See [Billing](/docs/billing/overview) for how the other plans
compare, and [exe.dev/pricing](https://exe.dev/pricing) for the full table.

## Getting started

Enterprise subscriptions are set up by contract. The minimum contract is one
entire host, though we're happy to start with a proof of concept (POC) first.
Email [support@exe.dev](mailto:support@exe.dev) to start one, to ask about a
BAA, or to make changes.
