Entuber · Enterprise Architecture · insights.entuber.com


FITS — The Enterprise SaaS Standard Built for Sovereignty

How Entuber delivers Fully Isolated Tenant SaaS across its enterprise application suite — giving every client their own platform, their own data, and their own process.

Most SaaS platforms ask enterprises to share infrastructure with hundreds of other clients. Entuber's FITS standard turns that model on its head — every client gets a sovereign, named instance from day one.

TerraVault

Soil Chain-of-Custody

TrainMe

Workforce Learning

Kairos

Project Intelligence

Explore FITS at insights.entuber.com

Why Shared SaaS Falls Short for Regulated Enterprises

Multi-tenant platforms create risks that regulated organisations cannot accept. When your records live alongside hundreds of other clients in shared infrastructure, the exposure is structural — not theoretical. For municipal utilities, regulated infrastructure operators, and enterprise clients, this is not an acceptable trade-off.

Shared Data Risk

Your records share database tables with every other client on the platform. A single misconfiguration — by you or another tenant — puts your data at risk. Physical separation is the only credible answer.

No Real Isolation

Logical separation is not physical isolation. A breach or failure in another tenant's environment can have a blast radius that reaches yours. "Isolated by policy" is not a security architecture.

Forced Conformity

Your business process must fit the vendor's shared model. Meaningful customisation requires a roadmap vote and a long wait — or a costly professional services engagement with no guarantee of delivery.

Vendor-Controlled Upgrades

Every client upgrades together, on the vendor's schedule. Your change management process and UAT window are irrelevant. Regressions become everyone's problem — including yours.

Introducing FITS

Four words. Four contractual guarantees. One delivery standard. FITS is not a marketing term — it is an architectural commitment, enforced at the infrastructure level and backed by contract. Every Entuber enterprise application is delivered to this standard, without exception.

F — Fully

Complete isolation — not logical separation. Your instance has its own compute, its own pipeline, and its own security boundary. No shared resources with any other client. Ever.

I — Isolated

Separate Azure App Registration, separate database, separate deployment pipeline. Your data is physically isolated from every other client at every layer of the stack — from storage to application tier.

T — Tenant

You are the sole tenant of your own named instance. Contractual data ownership, custom workflow configuration, and independent upgrade control. Your platform — not a shared login on someone else's.

S — SaaS

Despite the sovereignty, you get every SaaS benefit — zero infrastructure management, automatic platform monitoring, and onboarding in days, not months. Powered by Azure AI Foundry.

How FITS Works: The Golden Source Model

One canonical platform. Infinite sovereign client deployments. Azure AI Foundry stamps each new named instance automatically — in days, not months.

Tier 1 — Golden Source

Entuber's single enterprise-grade master platform: TerraVault · TrainMe · Kairos — Core compliance layer, chain-of-custody engine, integration framework, and AI modules. Maintained and upgraded centrally by Entuber.

Azure AI Foundry — Stamping Pipeline

Automated provisioning stamps each new client instance from the Golden Source. Separate Azure App Registration · Key Vault · Scoped RBAC provisioned per client. Onboarding in days — zero manual infrastructure setup.

Tier 2 — Named Client Instances

Each client receives a fully named, fully isolated deployment: TerraVault_MDC · TrainMe_CF · Kairos_[Client] — with independent Dev / Test / Prd environments, custom workflow configuration, and independent upgrade control.

Tier 3 — Per-Instance Infrastructure

Each instance runs on its own dedicated stack: Database · App Registration · Key Vault · Scoped RBAC. No shared resources. No shared compute. Physical isolation at every layer — from storage to application tier.

🔒 Full Sovereignty

Every client owns their instance. Contractual data ownership and independent upgrade control — always.

⬇️ Updates Without Risk

Security patches and platform improvements flow downstream as reviewed updates — never breaking client-specific configuration.

🚀 Enterprise-Grade by Default

Every instance inherits the full capabilities of the Golden Source — compliance, AI, and integration — from day one.

Entuber's Enterprise Applications

A suite of sovereign, FITS-delivered platforms — each purpose-built for regulated enterprise operations. Every application below is deployed as its own named FITS instance: fully isolated, contractually sovereign, and configured to your organisation from day one.

TerraVault · Soil Chain-of-Custody

End-to-end soil movement tracking for municipal water utilities and infrastructure projects. Digital Bill of Lading, 12-step chain of custody, weigh scale integration, SAP and GIS connectors, and full compliance reporting. Every load tracked from excavation source to final disposal — with an immutable audit trail.

TrainMe · Workforce Learning

A fully isolated LMS for certifications, safety compliance, role-based training paths, and workforce capability tracking. Each organisation gets their own named instance — learner records, course libraries, and compliance data are physically isolated from every other client. No shared records, ever.

Kairos · Project Intelligence

AI-driven project scheduling and resource management for complex multi-site operations. Constraint-aware timeline planning, skill-matched workforce allocation, SAP ERP integration, and real-time executive dashboards — all scoped to your sovereign instance. Named for the Greek moment of perfect timing.

The FITS Advantage

Core foundations. Customised footprint. Yet 100% SaaS. The FITS model resolves what enterprise buyers have long considered an impossible trade-off: the control and isolation of private infrastructure, delivered at the speed and economics of modern SaaS.

🏛 Core Foundations

Every Entuber application is built on a Golden Source — a maintained, enterprise-grade core platform with chain-of-custody, compliance, integration, and AI capabilities built in. Clients inherit best-in-class foundations without building from scratch. Security patches and platform improvements flow down automatically as reviewed updates — no manual porting, no fragmentation.

Customised Footprint

Every client instance is stamped and configured to their organisation — their workflow steps, their approval chains, their field configurations, their RBAC structure, and their integration endpoints. Azure AI Foundry provisions each named instance in days. The platform fits the client. Not the other way around. 12-step workflow or 11-step — your choice, your config, your ownership.

Yet 100% SaaS

No on-premise infrastructure. No internal IT team managing servers or pipelines. Entuber operates, monitors, and maintains every instance as a fully managed service. Clients get private-cloud-equivalent isolation and sovereignty — delivered, updated, and supported at SaaS speed. Own your process. Own your data. Leave the infrastructure to us.

"Sovereign by design. Delivered like SaaS."

TerraVault · Municipal Utilities · Infrastructure

TerraVault — Soil Tracking, Chain-of-Custody Compliant

End-to-end soil movement tracking — from excavation source through transfer facility to final disposal. Digital manifests match paper Bill of Lading formats. A 12-step BOL workflow tracks every load from field observation through receiver sign-off with a fully immutable audit trail. TerraVault is purpose-built for municipal water utilities and regulated infrastructure projects where provenance and compliance are non-negotiable.

Key Capabilities

  • 12-Step BOL workflow: CREATED → FIELD_OBSERVATION → SOURCE_WEIGH_OUT → MANIFEST_GENERATED → DISPATCHED → TRANSPORTER_SIGNED → IN_TRANSIT → ARRIVED → WEIGHED_IN → UNDER_INSPECTION → ACCEPTED → RECEIVER_SIGNED → CLOSED
  • Digital manifest with three-party signatures: Generator · Transporter · Receiver
  • Weigh scale integration — Mettler-Toledo SICS / Modbus TCP
  • SAP S/4HANA OData bidirectional sync
  • Esri ArcGIS site mapping and Geotab GPS fleet tracking
  • Lab sample tracking with exceedance alerts
  • RBAC for 400+ users · Full immutable audit trail
  • Hauler invoice reconciliation
12

BOL Workflow Steps

End-to-end load tracking from excavation to final disposal

400+

Users per Instance

Enterprise-scale RBAC scoped to your sovereign instance

6

Native Integrations

SAP, Esri, Geotab, Mettler-Toledo, and more

0

Shared Tables

Zero shared database tables with any other client. Ever.

TrainMe · Enterprise LMS · Compliance

TrainMe — Workforce Learning, Sovereignty Guaranteed

TrainMe delivers each enterprise a fully isolated learning management system — certifications, safety compliance, role-based training paths, and workforce capability tracking — all running in their own sovereign FITS instance. No shared learner records. No shared course libraries. Your workforce data stays yours, always.

Isolated LMS per Client

Each organisation gets their own named TrainMe instance. Course libraries, learner records, and certifications are physically isolated from every other organisation on the platform.

Compliance Certification Tracking

Role-specific compliance paths, expiry alerts, and regulatory reporting — configured to the client's workforce structure and industry requirements.

Capability Analytics

Real-time dashboards tracking workforce readiness, skill gaps, and certification status across departments and roles. Board-ready reporting at a glance.

HR & Identity Integration

Connects to your HRIS, Active Directory, and payroll system. SCIM provisioning syncs new hires into their training tracks automatically on day one.

Mobile-First Offline Delivery

Offline-capable mobile app for field workers. Training modules, assessments, and sign-offs work without network connectivity — built for the field, not the boardroom.

FITS Sovereign

Learner data never touches another organisation's records. Audit-ready from day one. Compliant by architecture, not by attestation or vendor promise.

Kairos · Project Intelligence · Resource Management

Kairos — The Right Resource, at the Right Time

Kairos — the Greek word for the opportune moment — gives enterprises a sovereign project scheduling and resource management platform. Each client instance is isolated, configured to their project structure, and connected to their existing ERP and workforce systems.

"The right platform, at the right time, for the right team."

Key Capabilities

  • AI-driven, constraint-aware project timeline optimisation
  • Skill-matched workforce and equipment allocation
  • Concurrent multi-site project management
  • SAP ERP integration for budgets and purchase orders
  • TrainMe integration — certification checks before worker assignment
  • Real-time executive dashboards scoped to your instance
  • Regulatory window and compliance deadline awareness

Intelligent Scheduling

AI-driven project timeline optimisation. Constraint-aware scheduling across resources, sites, and regulatory windows — automatically resolving conflicts before they escalate.

Resource Management

Allocate workforce, equipment, and budget across concurrent projects. Skill-matched assignments with live availability tracking and real-time conflict detection.

ERP & Field Integration

Live sync with SAP for budgets and POs. Connects to TrainMe for worker certification checks before assignment — no uncertified worker reaches the field.

Executive Dashboards

Real-time project health, milestone progress, and resource utilisation — scoped entirely to your sovereign instance, never commingled with other clients' data.

What Customers Gain

FITS delivers outcomes that traditional SaaS cannot match for regulated enterprise clients. These are not aspirational promises — they are architectural guarantees, enforced at the infrastructure level and backed by contract from day one of your engagement with Entuber.

Days

Time to Go-Live

From contract signing to fully configured, named instance — provisioned by Azure AI Foundry

100%

Data Ownership

Contractual data ownership retained by the client. Export or take your data at any time.

0

Shared Tables

Zero shared database tables with any other client at any layer of the infrastructure stack.

3

Isolated Environments

Dev · Test · Prd — three sovereign environments per named client instance, standard.

Data Sovereignty

Contractual ownership of every record. Export or take your data at any time. No vendor lock-in to shared infrastructure. Your records remain yours even after the contract ends — clean, portable, and fully attributable.

Process Ownership

Your workflow is configuration in your own instance — not a feature request on a shared roadmap. Customise approvers, steps, and field classifications without waiting on a vendor release cycle or negotiating with other clients.

Immediate Value

Azure AI Foundry provisions your named instance in days. Your team onboards to a fully configured system — no crawl, no walk. Straight to run. Enterprise capability without enterprise implementation timelines.

Regulatory Readiness

FedRAMP-ready architecture. SOC 2 Type II available on request. Immutable audit logs scoped only to your instance — clean for regulators from day one, by architecture rather than by attestation.

Your system.
Your data.
Your sovereignty.

FITS TerraVault · FITS TrainMe · FITS Kairos — every Entuber enterprise application, one sovereign standard. The era of asking regulated enterprises to share their infrastructure, their data, and their process with strangers is over.

TerraVault

FITS Soil Chain-of-Custody

TrainMe

FITS Workforce Learning

Kairos

FITS Project Intelligence

"Sovereign by design. Delivered like SaaS."