Deployment modes
REM runs wherever the security boundary requires. The same control plane supports every mode.REM-managed cloud
REM operates the deployment in an isolated environment.
Dedicated VPC
Single-tenant infrastructure with isolated networking and keys.
Customer cloud
Deployed into your cloud account, under your policies.
On-premises
Deployed inside your own data centre.
Embedded / OEM
REM runs as the white-label backend inside a vendor’s own product.
What stays with you
REM does not own customer funds, balances, wallets, keys, custody, issuance, regulated execution, or the final action.- Signing goes through an interface to your KMS, HSM, vault, or custodian. Local keys are used only in development.
- Execution of regulated actions remains with you, your bank, your custodian, or your licensed provider.
- Data is limited to the participant view you authorise, processed inside the boundary you define.
Control plane
- RBAC, service identities, secret management, and least privilege
- Data retention, residency, tenant isolation, and participant visibility controls
- Versioned schemas, mappings, policies, and workflows
- Metrics, logs, traces, alerts, incident evidence, and replay controls
- Encryption, isolated environments, and reproducible deployments
Correctness guarantees
- At-least-once ingestion with exactly-once business effects through idempotency
- Recovery without silent loss, and complete raw-to-action traceability
- Explicit finality, correction, and manual recovery semantics
- One nonce authority per signing address for any onchain write

