Critical systems engineering · Montpellier, France · since 2024

Sovereign private cloud expertise found nowhere else in France.

Long-term embedded engineering, architecture audits, support across your whole open source stack — on systems that are not allowed to fail. And because you only run well what you understand, we build the internal cloud we deploy on your side.

Our product

  • Self-service: your teams provision on their own
  • Sovereignty: data, logs and keys stay on your side
  • Budget: an amount known up front, with no usage billing

Our expertise

Three fundamental fields.

Data, security and governance, artificial intelligence. Three fields we design, audit and operate.

Data & Lakehouse

Data you can query, trace and move.

  • Medallion architecture, data vault, modelling
  • ETL, OCR, document ingestion
  • Iceberg lakehouse, Trino engine, catalogue and lineage
  • Streaming and high-volume processing
TrinoApache IcebergMinIOCeph

Security & Governance

Architectures where a leak is not an option.

  • Data stack and application security audits
  • Encryption, key management, multi-tenant segmentation
  • Fine-grained access control and audit trail
  • Tooling for the technical requirements of NIS2 and GDPR
KeycloakIstioCiliumcert-manager

Artificial intelligence

Your models on your side, your data never leaves.

  • In-house LLMs, on-premises inference and fine-tuning
  • GPU sizing and serving architecture
  • AI agents, pattern selection, MCP implementation
  • Sourced answers, structured extraction
vLLMTritonKServeKubeflow

See the three fields in detail

Open source

Our open source contributions.

s0

BUSL-1.1 · Apache-2.0 au 18 août 2030

An S3-compatible authorization gateway that applies an OPA/ABAC policy to every request before re-issuing it to storage under a per-tenant identity.

This is not a byte proxy with an authorization hook bolted on: the request is deserialized into a typed value, the decision is made on that value, and the same value is re-issued to storage. Of the 99 protocol operations, 23 are enforced and forwarded, 76 refused — there is no third category. A test fails if the table and the documentation drift apart.

talos-rust-client

MIT OR Apache-2.0

A gRPC client for SideroLabs Talos, with mTLS by default and a typed API generated from the official proto files.

Talos has no shell: you do not log into it, you talk to it. We needed this client to operate our clients' clusters.

trino-rust-client

Apache-2.0

A Trino client for Rust, with authentication and the spooling protocol.

Written and maintained by our engineers. Used in production inside Hyperfluid.

Ferris Key

Apache-2.0

An authentication and identity management server, written in Rust.

A community project we contribute to and sponsor.

Our open source expertise

  • Talos Linux
  • Kubernetes
  • KubeVirt
  • Argo CD
  • OpenTofu
  • Ansible
  • Rook-Ceph
  • CloudNativePG
  • PostgreSQL
  • Trino
  • Apache Iceberg
  • Kafka
  • Airflow
  • Cilium
  • Istio
  • Envoy Gateway
  • Keycloak
  • OpenBao
  • cert-manager
  • KServe
  • vLLM
  • Triton
  • Kubeflow
  • NVIDIA GPU Operator
  • LeaderWorkerSet
  • Grafana
  • Prometheus
  • OpenTelemetry

Every item on this list runs at a client under contract, runs inside Hyperfluid, or falls within our support contract. None is here on the strength of having read about it.

The problem

These skills cannot be hired one at a time.

A modern critical platform needs, at the same time: someone who knows the lifecycle of a cluster on an immutable system, someone who can size distributed storage, someone who has already watched a query engine collapse under load and knows why, someone who writes authorization policies rather than firewall rules, and someone who knows what it costs when a model does not fit on a single card.

Each of those profiles exists in small numbers. All five on the same team, available at the same time, in your labour market and on your salary scale: no. This is not hard recruitment, it is recruitment that does not conclude — and while it does not conclude, the platform runs anyway.

So what we rent is not engineering hours, it is a combination that already exists. It works together, it runs these components in production elsewhere, and it wrote part of the tooling it uses. Our engineers move into your teams for as long as it takes, and what they know stays when they leave.

Read the three articles

Missions

Quatre engagements, décrits par ce qu'ils ont produit.

Quatre engagements en cours ou clos, décrits par la pile qui tourne et par ce qu'elle a produit.

Forward Deployed Engineer · ongoing, more than 12 months

National banking group

An internal data platform rebuilt as code, as a GitOps flow, and self-service.

KubernetesArgo CDOpenTofuAnsibleGrafana

Advisory and implementation · ongoing

Montpellier computing centre

A Kubernetes base on an immutable OS, and a GPU inference chain for public research.

Talos LinuxKubernetesRook-CephCloudNativePGOpenBao

Sovereign cloud · ongoing

Montpellier Métropole

A data and inference cloud operated under public control.

KubernetesvLLMKeycloakPostgreSQLMinIO

Data & AI · fixed-term engagement

Industrial group

A heterogeneous document base made searchable, every answer citing its document.

TrinoApache IcebergOCRpgvectorMCP

Voir les quatre missions en détail

Partners and networks

Two software vendors, two networks, five institutions.

Internal communication

Elvinck

Internal communication platform to connect and engage teams.

SaaS billing

Meteroid

Usage-based billing and revenue recognition for software vendors.

Networks

Incubation

Financing

Get in touch

Talk to an engineer, not to a form.

Three paths, depending on what you are after: Hyperfluid, engineers embedded in your teams, or a data stack or security audit. The address below reaches the engineers directly.

contact@nudibranches.tech