NetThunder portfolio

Choose the right platform.

Start with where the work runs and what you need to manage. Spark™, SecureEnclave™, CloudSpawn™, and Storm™ are four distinct platforms for different operating needs.

Workload, boundary, and capacity

Find your starting point.

Compare the operating shapes, then follow the platform that fits your work.

Operational edge and private virtualization

Spark™

Spark™ places a complete, customer-controlled operating environment on one supported node for operational edge deployments, OT trust zones, and private virtualization workloads.

Operating shapeOne node connects every path.
  • OT networks
  • Devices
  • Workloads
  • Data paths
One supported nodeComplete environment
Private virtualizationApplications + servicesRequired + observed state
The selected design defines the trust zone, runtime, connections, capacity, and operating authority.
Best fit
Operational edge deployments, OT zones of trust, and qualified private-virtualization targets.
Operating shape
One supported node carrying one complete, customer-controlled operating environment close to the work.
What it manages
Configures the supported applications, services, resources, and dependencies on the node, then applies and records changes to their state.
Configuration details

Control and boundary: The design defines which networks, devices, workloads, data, administrative paths, and operating responsibilities belong together.

  • Hardware and storage
  • Hypervisor and runtime versions
  • Device and network support
  • Capacity and resilience
  • Connectivity and support paths
  • Migration and acceptance plan

The deployment design qualifies the selected host, runtime, paths, capacity, resilience, access, support, and validation criteria.

Explore the full Spark™ platform

CMMC and controlled workflows

SecureEnclave™

SecureEnclave™ makes the selected CUI boundary operable as one controlled environment across applications, safeguards, identity, telemetry, recovery, and responsibility.

Operating shapeWorkflows define the controlled boundary.
Approved pathIdentity + policy
Selected CUI boundary
Approved applicationsProtected dataManaged stateTelemetry + evidenceRecovery scopeOperating controls
Human responsibility Authorization · risk · exceptionsIndependent assessment In-scope implementation
The approved design keeps technical state, evidence, recovery, and responsibility connected without turning human judgment into an automated claim.
Best fit
CUI and sensitive workflows whose applications, safeguards, evidence, recovery, and responsibilities must stay connected.
Operating shape
One controlled environment and managed boundary organized around the selected CUI workflow.
What it manages
Maintains the selected environment's configuration, safeguards, technical evidence, and supported recovery operations as its state changes.
Configuration details

Control and boundary: Physical, logical, identity, administrative, data, evidence, recovery, and responsibility scope are defined together while authorization and assessment remain human decisions.

  • In-scope people, systems, and data
  • Approved applications and safeguards
  • Identity and administrative paths
  • Connectivity and transfer modes
  • Telemetry and technical evidence
  • Recovery tests and responsibilities

The approved design defines the CUI scope, components, safeguards, connectivity, evidence, recovery, and operating responsibilities.

Explore the full SecureEnclave™ platform

Elastic supercomputing orchestration

CloudSpawn™

CloudSpawn™ orchestrates elastic, supercomputer-class infrastructure as a complete software-defined tenant environment across supported bare-metal compute, accelerators, high-performance data fabrics, and parallel storage.

Operating shapeSoftware-defined bare metal, isolated by tenant.
Other tenantsProvider administration
CloudSpawn™ boundaryTenant authority
WorkloadDataTopologyPolicy
Paired platformStorm™ manages this cluster
Bare-metal compute + acceleratorsParallel storageHigh-performance fabricAI + services
Cloud-provider physical service remains outside tenant administration. Scoped support follows the procedures approved for the tenant environment.
Best fit
AI, research, engineering, and HPC workloads that need workload-shaped bare-metal compute, accelerator capacity, and high-performance data paths with hyperscaler-style elasticity.
Operating shape
An isolated, software-defined tenant environment serving elastic, supercomputer-class bare-metal infrastructure as workload requirements change.
What it manages
Orchestrates tenant resources, services, identity, policy, and lifecycle as workload and capacity requirements change.
Configuration details

Control and boundary: Isolation spans resources, identity, state, data, control paths, telemetry, support, and physical service, separating the tenant environment from other tenants and cloud-provider administration.

  • Workload, data, and services
  • Capacity profile and topology
  • Supported bare-metal resources and fabrics
  • Parallel storage and workload services
  • Lifecycle approvals and failure handling
  • Recovery and acceptance criteria

The tenant design qualifies supported resource classes, topology, services, isolation, lifecycle controls, support procedures, and validation criteria.

Explore the full CloudSpawn™ platform

Cluster management

Storm™

Storm™ is NetThunder's scheduler-agnostic cluster-management software for provisioning supported bare-metal infrastructure and maintaining configuration as nodes, applications, and requirements change.

Operating shapeDeclare the cluster. Realize it on bare metal.
Authorized inputsService definitionsResources + topologyDependencies + state
Cluster management platformStorm™
Managed resultBare-metal workloads + servicesQualified cluster stateLifecycle controls
The selected design defines the supported resources, application scope, out-of-band control path, lifecycle actions, performance criteria, responsibilities, and acceptance tests.
Best fit
Existing and new HPC, research, engineering, and AI clusters whose owners want repeatable deployment and less manual configuration work.
Operating shape
Controller software, supplied on physical controllers or as installation images for qualified customer nodes, that configures and manages a bare-metal cluster.
What it manages
Re-images selected bare-metal nodes, configures storage-backed boot and user-defined software stacks, and calculates changes from software packages and their dependencies.
Configuration details

Control and boundary: The cluster specification defines resources, services, control paths, approvals, state, and operating responsibilities. Any enclosing tenant or security boundary remains explicit.

  • Resource classes and topology
  • High-performance fabric and storage paths
  • Services and dependencies
  • User-defined schedulers and software stacks
  • Lifecycle approvals
  • Failure and recovery behavior

The deployment design qualifies the cluster resources, integrations, lifecycle actions, control paths, responsibilities, and acceptance criteria.

Explore the full Storm™ platform

An integrated AI appliance

Choose where AI runs.

Storm AI Factory™ is an AI operations module offered as a standalone appliance for your existing infrastructure, on premises or in colocation. It includes Storm™ infrastructure management and open-source AI software for inference, training, and agents.

It is also included with CloudSpawn™ and available in selected Spark™ and SecureEnclave™ configurations. Storm™ cluster owners can run AI applications without the AI Factory appliance.

Storm AI Factory™

Run AI workflows.

Create controlled sandboxes, train models, run inference, and operate agents within the selected environment.

Spark™
Selected configurations
SecureEnclave™
Selected configurations
CloudSpawn™
Included
Review the AI Factory module

Operating authority

Know who controls what.

A customer-controlled operating environment defines operating authority and responsibilities independently from hardware title.

Location
Where infrastructure is placed and where data is stored or processed.
Administration
Who administers the environment and which privileged paths are permitted.
Identity and policy
Who may access the environment, which connections are allowed, and how changes are approved.
Provider access
What access a provider requires, when it may be used, and how it is recorded.
Observation and audit
What the customer can observe, approve, restrict, isolate, and audit.
Title and financing
Record commercial and hardware-title terms as their own control dimension alongside operating authority.

Architecture review

Match platform to workload.

Tell us what needs to run and where. Start with a conversation about platform fit, open questions, and the design decisions ahead.

Email NetThunder +1 847.477.7676