PARTNERS

Add selected Workbench capabilities through bounded OEM and partner integrations

OEM-04

OEM Deployment Spectrum

OEM delivery can progress from hosted API access through local workers and embedded sidecars to controlled private deployment.

ordered spectrum

LOWERHIGHERHosted APIThe partner invokes a hostedcapability through an agreedcontract.Partner-local workerSensitive execution remains in thepartner or customer environment.Embedded sidecarSecEng capability runs inside thepartner product workflow.Private deploymentDedicated or isolated deploymentwith increased operatingresponsibility.TRADEOFFSPartner and customer controlincreasesIntegration depth increasesOperating responsibilityincreasesSupport boundary becomes morespecific

About this figure

OEM delivery can be understood as a spectrum of deployment models, each trading vendor-managed simplicity for partner control and integration depth. At one end, a hosted API offers the fastest path to adoption with minimal operational burden, but limited customization and the broadest support boundary. Moving inward, a partner-local worker keeps execution closer to the customer environment while preserving much of the vendor’s operational responsibility. An embedded sidecar increases integration depth further by colocating capabilities within the customer stack, tightening the support boundary and expanding partner control. At the far end, private deployment gives the customer the most control and isolation, but also shifts the greatest operational responsibility to the deployment owner. Across the spectrum, control, integration depth, and responsibility all increase together, while the vendor support model becomes progressively more specific and constrained.

Embed in a route

<FigureFromSource sourcePath="content/publications/figures/partners/oem-expansion.dsl.md" figureId="OEM-04" />

Citation

OEM Deployment Spectrum (OEM-04). AI Security LLC Figure Library. https://aisecurity.llc/publication-dsl/figures/OEM-04