Hyground - Enterprise AI Operations
Hyground GmbH · Cybersecurity & IT
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
Hyground Core is an enterprise-ready AI workspace and intelligence layer for operations. It runs fully inside your environment and augments your existing observability stack with autonomous analysis, guided investigation, and natural language interaction.
Hyground is deployed via Helm into your infrastructure and operates within your security perimeter. The platform integrates through a modular adapter layer with Prometheus, Loki, OpenSearch, Alertmanager and other systems. By default, it uses a read-only Service Account to ensure it cannot modify cluster state.
Show the rest of the publisher’s description (15 more lines)
Core capabilities include:
AI-Powered Root Cause Analysis
Hyground correlates logs, metrics, state and documentation to autonomously investigate incidents and generate structured, evidence-backed hypotheses. This reduces manual triage effort and shortens mean time to resolution.
Natural Language "Talk to Your Infrastructure"
Engineers can query their systems in plain English via a conversational interface. Hyground translates intent into structured analysis across telemetry sources and returns clear, actionable insights.
Comprehensive System Overview and Visualization
Hyground provides real-time infrastructure health summaries, resource utilization views and automatically generated visualizations to support decision-making.
Knowledge-Enriched Analysis (RAG-ready)
The platform can connect to internal documentation such as Confluence to enrich investigations with environment-specific context.
Security and Compliance
Hyground is designed for private-cloud or on-premises deployment and keeps your telemetry, session data, and embeddings inside your AWS environment — session and knowledge-base data in PostgreSQL, agent memory on Kubernetes persistent volumes. Encryption in transit is enforced via TLS. Encryption at rest is governed by your AWS storage and database configuration (e.g. Amazon EBS and Amazon RDS / Aurora PostgreSQL with AWS KMS). When paired with Amazon Bedrock, model inference stays within your AWS account and region. Authentication integrates with your existing SSO via OAuth2/OIDC and is compatible with any OIDC provider, including AWS IAM Identity Center. All external adapters are read-only by design and verified at startup; Kubernetes access is RBAC-bound to the read-only service account you provide, so Hyground cannot modify cluster state.
Technical Requirements
Amazon EKS is fully supported (Kubernetes ≥1.27, Helm ≥3.12). Requires PostgreSQL ≥17 with the vector (pgvector) extension for session and embedding storage — Amazon RDS for PostgreSQL or Amazon Aurora PostgreSQL recommended — plus access to a LiteLLM-compatible model such as Amazon Bedrock. Minimum cluster resources: 3 vCPU / 4 GB / 5 Gi storage (single user); 4 vCPU / 6 GB for standard deployments with authentication and knowledge base.
Implementation & Support
We provide implementation and support for the Hyground Core AI workspace running on Amazon EKS — including Helm deployment, IRSA and RDS/Aurora configuration, observability adapter setup (Amazon Managed Service for Prometheus, Amazon OpenSearch Service, Amazon CloudWatch), and integration with Amazon Bedrock as the model backend.
Highlights
Highlighted by the publisher on AWS Marketplace.
100% Data Sovereignity - cloud/on-prem installation keeps all your sensitive data in your control. no third-party or external storage
Instant Root Cause Analysis - automatically starts investigation within seconds of an alert, delivers findings and next steps within minutes
Cost Savings - cut failure resolution times by up to 70%, reduce unplanned downtime, lower on-call and operational costs
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Sources
Linked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

