DATACENTER AS AN APPLICATION™

hero engine

Fits Your Enterprise. No Re-Architecture Required.

STRATUM is designed to work with the enterprise platforms you already trust. Tools such as Veeam and Zerto can continue supporting continuous data protection, backup and recovery, disaster recovery, and ransomware resilience, while Splunk and other security, observability, and centralized management platforms remain part of your existing operational ecosystem.

When STRATUM is deployed on Kubernetes, it can integrate with the same enterprise tools already supporting your Kubernetes environment. When it runs as an OCI container on a standalone Linux server, traditional infrastructure tools can still back up, restore, monitor, analyze, and secure the host, its virtual machines, and its running containers—including STRATUM itself. STRATUM does not require you to redesign the enterprise around a new infrastructure stack. It extends what you already have, preserves existing investments and operational practices, and gives you a modern virtual-datacenter platform without creating another isolated management silo.

Mixed x86 and ARM - One Unified Fabric

STRATUM brings x86 and ARM infrastructure together in a single virtual machine fabric—not just a container platform. Workloads can run natively on either architecture or be emulated across architectures, giving organizations the freedom to balance performance, power efficiency, cost, and hardware availability without creating separate infrastructure silos. It is a game changer because mixed-architecture computing becomes flexible, portable, and practical across both datacenter and edge environments.

mixed fabrics

Infrastructure, Rebuilt as Software

STRATUM does not simply run VMs inside a container—the container is the hypervisor, network fabric, security stack, and virtual datacenter. Compute, switches, routers, firewalls, and even the logical wiring are packaged into one portable immutable OCI image that can move through the same DevSecOps pipeline as an application. Updates arrive as efficient deltas via immutable layers, every release can be scanned and documented with an SBOM, and complete infrastructure can be deployed consistently from datacenter to edge. STRATUM transforms infrastructure from slow, handcrafted hardware integration into a secure, versioned, rapidly releasable software product.

infra as software

Intelligent Memory Deduplication

RAM is expensive. STRATUM identifies identical memory pages across virtual machines and stores only one shared copy, eliminating unnecessary duplication. The result is higher VM density, better memory utilization, and lower infrastructure cost—without changing the applications or operating systems running inside each VM. STRATUM does require supporting hardware for this feature. 

memory dedupe2

INFRASTRUCTURE IS NO LONGER BACKGROUND

Mssions do not run on intent alone. They run on systems, dependencies, and environments that must be built, understood, and controlled before anything above them can succeed. STRATUM turns that hidden substrate into an operational surface. 

The network is the container.

A complete virtual infrastructure — machines, switches, routers, wiring, and segmentation — can be delivered and scaled through the same operational model as modern software.

Operational visualization before execution.

See the deployment before it ships. Validate topology, templates, and segmentation in an environment built to be understood before it is launched.

The GPU is a first-class citizen.

STRATUM treats GPU-backed workloads as native infrastructure from the ground up, not as a fragile add-on to a legacy virtual stack.

Federation-ready

Run across cloud, on-prem, and remote sites without splitting the platform into disconnected islands of control.

multisite2

Multi-Site Quick Connect

STRATUM connects datacenter, cloud, remote, and edge environments into one unified virtual infrastructure—without the complexity of traditional mesh networking. A lightweight deployment model brings distributed sites together as a single virtual datacenter, making expansion, workload mobility, and remote operations dramatically simpler.

mem encryption

Hardware-Backed Memory Encryption

STRATUM protects virtual machine memory with hardware-backed encryption, keeping sensitive workloads isolated—even from the host and other tenants. By supporting confidential-computing technologies across modern x86 platforms, STRATUM helps secure data while it is actively being processed, not only when stored or transmitted.

disk encryption

Encrypted Virtual Disks

STRATUM protects virtual machine storage with strong encryption, securing operating systems, applications, and data at rest. Each virtual disk remains protected from unauthorized access, helping safeguard sensitive workloads across datacenter, cloud, and edge environments.

Why a Container?

The host becomes the commodity. STRATUM becomes the datacenter.

Building a new hypervisor is difficult. Getting one approved for enterprise, government, and regulated environments is harder.
A traditional virtualization platform often brings its own operating system, hardening baseline, patch cycle, configuration model, and security boundary. That means another platform to certify against GDPR, NIST RMF, SOC 2, DoW requirements, and internal corporate policy. In many environments, obtaining a new Authority to Operate (ATO) can take months—or longer.

STRATUM takes a different path.
You bring the host operating system your organization already trusts: a hardened Linux golden image, an approved enterprise build, or a platform that already holds an ATO. STRATUM is delivered above that foundation as a containerized infrastructure application rather than another operating system you must adopt, secure, and maintain.

That changes the accreditation equation.
STRATUM can move through the same trusted software supply chain as other mission and enterprise applications: built as an OCI image, scanned for vulnerabilities, accompanied by an SBOM, identified by immutable digests, and promoted through established registry and DevSecOps pipelines. Iron Bank–aligned base images and industry-standard container security practices provide a familiar path for review, evidence generation, and rapid adoption.

The result is not simply a hypervisor inside a container. It is the enterprise virtualization layer—compute, storage, networking, security, and infrastructure control—delivered as software.

Virtualization once turned physical hardware into a commodity. STRATUM goes further: it turns hypervisors, clouds, host platforms, and infrastructure environments into interchangeable foundations beneath one consistent operational layer.

Storage-as-a-Service, Built into the Fabric

STRATUM eliminates the need to engineer, deploy, and manage a separate SAN or NAS. Every STRATUM instance shares storage through a standards-based fabric built directly into the hypervisor—no guest OS configuration, storage accounts, or additional management layer required. Virtual machines can boot directly from images stored across the network, without host-side mounts, manual LUN mapping, or a separately provisioned shared-block layer. STRATUMvisor accesses each VM image in place and presents it directly to the workload.

Because the fabric is based on industry-standard iSCSI protocol, organizations gain established security controls and a cleaner path through STIG and NIST RMF assessment. Storage stops being another infrastructure project and becomes an integrated service available wherever STRATUM runs.

storage fabric

VM Storage, Reimagined for Hyper-Scale

To build a truly modern, hyper-scaling infrastructure platform, STRATUM had to change how virtual machines access storage. Every VM begins with an immutable, read-only template, while each individual workload stores only its unique changes in a lightweight child image. The common operating system and application base is stored once and shared across many VMs—eliminating massive amounts of redundant data without sacrificing isolation.

Backing files, copy-on-write, compression, and space-efficient snapshots are not optional add-ons; they are fundamental to the STRATUM architecture. The result is faster VM creation, dramatically lower storage consumption, simpler recovery, and infrastructure that can scale far beyond traditional one-disk-per-VM designs.

storage reimagined

Turn Infrastructure into a Rapid-ATO Software Release

STRATUM changes the compliance equation. Instead of introducing another massive bare-metal platform that must be hardened, documented, and assessed from the ground up, STRATUM builds on what organizations already trust: an existing hardened Linux host and a pre-vetted Iron Bank OCI image moving through established DevSecOps pipelines.

What remains is a remarkably small assessment surface—a focused set of STRATUM binaries and configuration files that deliver far more than a hypervisor. When built and operated in FIPS mode, STRATUM uses FIPS-approved cryptographic algorithms through the Go FIPS 140-3 Cryptographic Module, aligning its cryptographic foundation with modern federal security expectations.

STRATUM packages the storage fabric, encrypted network fabric, virtual switches, routers, firewalls, and even the logical wiring of the datacenter as software. The result is infrastructure that can be scanned, versioned, promoted, and continuously updated like an application—opening a practical path to Rapid ATO and Continuous ATO instead of another years-long certification effort.

compliance

The Datacenter, Delivered Like Software

STRATUM replaces the monolithic hypervisor release with a content-addressed OCI infrastructure platform. The hypervisor, storage fabric, encrypted networking, virtual switches, routers, firewalls, orchestration, and logical wiring are packaged and distributed through the same registry model enterprises already use for applications.

Each manifest references immutable layers by SHA256 digest. When a new STRATUM release is published, unchanged layers are reused and only new or modified layers need to be fetched. The result is faster distribution, smaller updates, verifiable releases, and infrastructure that can move through modern DevSecOps pipelines instead of being installed and maintained like it was twenty years ago.

container delivery

BUILT FOR MODERN INFRASTRUCTURE, NOT LEGACY VIRTUALIZATION ASSUMPTIONS 

STRATUM borrows the discipline of modern software delivery and applies it to virtual systems. Runtime is stateless. Persistent configuration and virtual machine data live outside the runtime layer. Updates move as image changes and deltas, not patch weekends and brittle runbooks.

STRATUM started from the drawing board

Instead of virtualizing only the server, STRATUM virtualizes the datacenter at the ground level: compute, storage, switching, routing, firewalls, GPUs, firmware, physical locations, port connections, and the wiring between them. The interface becomes a living network diagram—not a list of unrelated VMs hidden behind layers of configuration.

Plug a virtual wire from port 2 on a server into port 13 on a switch. Apply your site policy to that switch port. Attach a disk image that resides across the network. Assign GPUs from another rack, another building, or another cloud. Connect another datacenter by running a small STRATUM component at the remote site.

That is next-generation virtualization: not merely virtual machines, but the datacenter itself delivered as software.

A Datacenter in a Container

Yes, it is.
STRATUM manages storage across hundreds or thousands of hosts and virtual machines. It connects STRATUM systems across a datacenter, across multiple physical sites, and into cloud and edge environments. It delivers switching, routing, firewalls, encrypted fabrics, operations, orchestration, and even the logical wiring and cabling between systems.

It also creates a shared GPU fabric where CPU-only servers can access compute located elsewhere in the rack, elsewhere in the datacenter, at a remote physical location, or in the cloud.

And it does all of that as a portable OCI-delivered infrastructure engine.

Can you say that about your own datacenter?

Legacy

Legacy virtualization platforms have spent decades polishing the same model: hosts, clusters, storage layers, management servers, software-defined networks, add-on orchestration, and more configuration wrapped around every new capability.

Cloud, containers, Kubernetes, AI, and rack-scale computing changed the world around that model.

Virtualize the Datacenter - Not Just the VM

STRATUM does not ask organizations to abandon their VMware investment. It gives VMware an entirely new place to run.

By virtualizing the datacenter itself, STRATUM provides the network, storage, switches, ports, serial connections, wiring, cabling, and compute substrate beneath VMware ESXi. That virtual datacenter can span existing Linux systems, on-premises infrastructure, edge environments, and cloud resources across AWS, Google Cloud, Oracle Cloud, and Azure.

The result is true coexistence: keep the VMware tools, skills, and workloads your organization already depends on, while extending them onto a portable, software-defined datacenter fabric. STRATUM is not simply another layer for running virtual machines—it virtualizes everything those virtual machines depend on, even VMware itself. 

virtualize datacenter

STRATUMvisor
The Hypervisor Built Into the Virtual Datacenter

Traditional hypervisors virtualize servers. STRATUMvisor virtualizes everything those servers depend on.
What it is
STRATUMvisor is STRATUM’s integrated virtualization engine, delivered in the same portable OCI container image, without a separate hypervisor product, licensing tier, or management stack.
Under the hood
It uses KVM on Linux across x86 and Arm, with Hyper-V acceleration on supported Windows hosts. STRATUM adds its own orchestration, device models, storage fabric, networking, and virtual datacenter controls.
What makes it different
STRATUMvisor goes beyond VMs. Images are accessed directly through the integrated storage fabric, without host mounts, manual LUN mapping, or separate storage clients.

Ports, cables, switches, and connections are first-class virtual objects. Instead of assigning a VM to an abstract network, you wire specific VM ports to specific ports on switches, routers, firewalls, and other systems.

stratumvisor

The result

Compute, storage, networking, device access, and topology operate as one platform. Eliminating a separate hypervisor stack and replacing fragmented infrastructure management with one unified virtual datacenter.

STRATUM Security Imperative

STRATUM can run inside a gVisor sandbox, adding a powerful isolation boundary between the STRATUM container and the Linux host beneath it. That extra layer helps reduce the risk of container escapes, privilege escalation, and multi-tenant exposure while preserving the efficiency and portability of a containerized platform.

The result is defense in depth for the entire STRATUM infrastructure engine—hypervisor, storage, networking, and orchestration—not just for an individual application. With secure-by-default execution, runtime monitoring, broad x86 and Arm support, cloud-native deployment, and GPU/CUDA compatibility, STRATUM can bring stronger isolation to security-critical, AI, edge, and regulated environments without giving up the operational simplicity of containers.

security1

Orchestration Proven at Supercomputer Scale

STRATUM builds its orchestration fabric on Slurm, the fault-tolerant workload manager proven in some of the world’s largest supercomputing environments. It schedules compute, memory, GPUs, priorities, reservations, accounting, and execution across heterogeneous infrastructure.

A single STRATUM controller can orchestrate more than 65,000 nodes, while additional controllers extend capacity across sites and mission domains. Slurm provides active/standby controller failover; STRATUM adds continuous health monitoring, node isolation, reconciliation, and workload recovery.

Workloads can be placed across mixed x86 and Arm systems, CPU-only nodes, locally attached GPUs, and GPUs delivered through the STRATUM Accelerator Fabric. Architectures and accelerator types become intentional scheduling choices, not separate infrastructure islands.

The result is resilient orchestration that places each workload on the right resource, accounts for every allocation, and scales from a small edge deployment to a globally distributed compute fabric.

STRATUM provides the virtual datacenter. Slurm gives it the discipline to operate at scale.

orchestration

Connect Infrastructure Without Inheriting Its Boundaries

Draw the network once. Run it across everything.
STRATUM Continuum turns datacenters, clouds, remote sites, and edge systems into one encrypted virtual network mesh.

Your physical network provides reachability. STRATUM extends Layer 2 connectivity with VXLAN, making VMs, switches, routers, firewalls, and networks behave as one datacenter across dissimilar infrastructure.

STRATUM Connect uses the Go FIPS cryptographic module and STRATUM’s tunnel protocol to protect control traffic, orchestration, consoles, and inter-node communication. VXLAN carries the virtual Ethernet fabric above it.Existing networks and site addressing remain untouched. Overlapping networks coexist inside isolated virtual segments.

VM port → STRATUM bridge → VXLAN → encrypted STRATUM Connect → any datacenter, cloud, or edge site

STRATUM automates identity, keys, enrollment, addressing, and mesh connectivity. Your physical network provides reachability. STRATUM provides the datacenter.

network

GPU and Storage Fabrics, Built Into STRATUM

Storage over the network. GPUs over the network. Both presented as though they were local. STRATUM turns local disks, mounted filesystems, Kubernetes storage, cloud volumes, and enterprise storage into one distributed virtual storage fabric. VMs access that capacity across the cluster as though their disks were local.

The same philosophy applies to GPUs.
Traditional GPU-over-IP requires separate services, endpoints, firewall rules, remote-server tracking, and software inside every workload. STRATUM replaces that complexity with a purpose-built paravirtual GPU device presented directly to the VM.

To the guest, it behaves like attached hardware. Behind the scenes, STRATUM selects an available GPU, routes CUDA and management calls, and handles transport automatically.

Other platforms: Deploy and manage GPU-over-IP.
STRATUM: Attach a GPU device and let the platform handle the rest.

The GPU may be local, in another rack, at a remote site, or in the cloud. The VM does not need to know its address, endpoint, or transport path.

Traditional PCI passthrough remains available for workloads requiring direct ownership. The GPU fabric goes further, turning GPUs across the environment into shared, schedulable resources.

stratum gpu

Shared 3D Acceleration, Built Into STRATUM

Shared host graphics. Virtualized for every workload that needs it.
STRATUM can give virtual machines accelerated 3D graphics through its integrated virtio-gpu-gl stack. Guest graphics commands are passed through the virtual GPU to VirGL and translated into OpenGL calls on the host, allowing multiple VMs to share available graphics acceleration without dedicating an entire physical GPU to each workload.

This is designed for graphical desktops VMs, visualization, Android environments, engineering tools, and other OpenGL-based workloads—not CUDA compute. The graphics capabilities exposed to the VM depend on the GPU and driver stack available to the STRATUM host. When STRATUM itself runs inside another hypervisor (not sure why you would do that, but it does work), the outer platform must also expose a sufficiently capable virtual 3D device and OpenGL implementation.

3daccel

Zero Trust, Built Into the Virtual Datacenter

STRATUM treats every workload, session, and connection as an explicit security boundary—not as trusted simply because it sits inside the network. Server isolation, encrypted inter-site fabrics, segmented virtual networks, and tightly controlled console access reduce broad network exposure while keeping each virtual datacenter separated by design.

No implicit trust. No flat network. Access only to the infrastructure and sessions that are actually authorized.

zerotrust

Update the Fleet Like an Application

STRATUM turns infrastructure updates into a modern software release. Publish a new OCI image to your registry, roll it out across hundreds or thousands of nodes on your schedule, and automatically recover with rollback if something fails.

Because STRATUM is distributed as content-addressed OCI layers, unchanged data is reused and only new or modified layers need to move across the network. A multi-gigabyte platform update could require only a few megabytes of transfer—making fleet-wide deployment practical even across remote sites, edge systems, ships, aircraft, and bandwidth-constrained satellite links.

One release. Thousands of nodes. Only the change moves.

updatescale

STRATUMOPS: See the Mission, Not Just the Machines

STRATUMOPS is infrastructure operations as a living, temporal mission model, not another dashboard full of disconnected metrics. Schedulers like Slurm can tell STRATUMOPS where computation is running. STRATUMOPS tells it what that computation means.

STRATUMOPS fuses scheduler data, VM state, tenants, virtual datacenters (VDC), networks, distributed GPU leases, remote sites, and dependencies into a live operational graph. It does not just show systems connected by lines—it shows ownership, lineage, health, history, mission context, and blast radius.

With real-time graph updates, historical topology, mission replay, alerts, workflow automation, and failure-impact analysis, STRATUMOPS can answer the questions traditional infrastructure tools cannot:

What is running? Where is it running? What does it depend on? Operational lineage? Who owns it? And what breaks when this asset fails? What systems are affected by this template?

stratumops

The Network Becomes Part of the Virtual Datacenter

STRATUM can run familiar virtual network appliances from Cisco, Palo Alto, Arista, and other vendors—but it also includes its own purpose-built Layer 2 switch, engineered from the ground up for the STRATUM fabric.

Every interface is a first-class object on the canvas. Drag a wire from a VM into a specific switch port, configure that port, inspect its state, mirror its traffic, or capture packets directly. The topology is no longer documentation sitting beside the infrastructure. It is the infrastructure—a living network diagram that can be deployed, operated, and versioned.

Real Switching Without the Appliance Weight

STRATUM Switch delivers VLAN-aware forwarding, access and trunk ports, private VLANs, protected ports, RSTP, BPDU Guard, LLDP, LACP port channels, IGMP and MLD snooping, SPAN, direct PCAP capture, port security, impairment controls, and deep operational visibility.

It provides the switching capabilities needed for real datacenter and laboratory networks without carrying the operational weight of a full network operating system. The hardened static binary is approximately one megabyte, yet still exposes the forwarding state, topology, counters, neighbors, captures, fabric endpoints, and diagnostic information operators expect.

stratumswitch tech

Distributed by Design

STRATUM Switch is not restricted to one host. Its native Slurm execution path places switches on the right worker, creates local TAPs and bridges, establishes VXLAN connectivity, integrates with STRATUM Continuum (Network Mesh), and cleans up the complete runtime when the workload ends.

A switch can span workers, sites, clouds, and edge systems while remaining one logical object on the canvas.

STRATUM does not merely virtualize network appliances. It virtualizes the ports, links, policies, and physical relationships that make the network real.

Bring the Hypervisor to the Compute. Bring the GPU to the VM

STRATUM runs across AWS, Google Cloud, Oracle Cloud, Azure, and Kubernetes-native AI neo-clouds such as CoreWeave—using the cloud as interchangeable compute beneath one consistent virtual datacenter. Because STRATUM is delivered as a container, deploying it into cloud and Kubernetes environments is a natural extension of the platform rather than a separate product architecture. CoreWeave, for example, exposes its GPU infrastructure through a managed Kubernetes service running on bare metal.

The disruptive shift is GPU placement. Your STRATUM VMs do not need to run on the same expensive cloud host that owns the GPU. Standard KVM-capable workers can run the virtual machines while smaller, purpose-selected GPU cloud-instances provide acceleration through the STRATUM GPU Fabric. AWS now supports nested KVM on selected virtual EC2 instances, while major clouds offer dedicated, full, and fractional GPU options.

Run compute where it is economical. Acquire GPUs where they are available. STRATUM makes them operate as one infrastructure fabric.

clouds

PATENT PENDING