Sell obstruo, or deploy it for your clients
Regulated organisations rarely roll this out themselves. Partners resell obstruo, connect it to the client's apps and providers, and configure the routing and redaction policy the client has to defend. The account, the keys and the audit log stay with the client.
Five kinds of partner, one product to deliver
Some partners sell obstruo, some deploy it, some do both. The work is the same shape: get the client's AI traffic behind one endpoint they control, and get the policy right for their jurisdiction.
You design the client’s AI governance model: risk tiers, approval gates, ownership. obstruo is the product you deploy so the model you wrote is actually running on the client’s traffic, not sitting in a document.
You take clients through an AI management system: scope, controls, internal audit, certification. The audit trail from obstruo gives you dated operational records instead of screenshots and self-attestation.
You run the DPIA, decide the lawful basis, classify the system. obstruo is where those conclusions turn into per-country redaction and EU-only routing on the client’s live traffic.
You build and run the client’s AI platform. Putting obstruo in front of it means one key and one endpoint for every app, with provider keys and routing rules you can change without a deploy.
You already operate infrastructure for regulated clients. obstruo becomes another managed service: you deploy it, tune the policies, and handle provider key rotation on the client’s behalf.
obstruo builds and runs the enforcement layer. We do not sell advisory work, audits or implementation projects, and we refer that work to partners instead of competing for it.
A normal software deployment, done by you
The client gets an obstruo account. Your engineers work in it as members the client invites, with the roles the client chooses.
Refer the opportunity and take a fee, or resell obstruo on your own paper. Either way you get the technical pre-sales support, the security documentation and the pricing to quote from.
Load the client’s provider keys into their account, point their apps at one obstruo endpoint, and migrate them off keys scattered across services. Most of the work is one base URL and one key per application.
Which providers answer which traffic, what happens when one is degraded, which regions EU traffic may leave to, and which PII categories are stripped for each jurisdiction the client operates in.
The account, the provider keys and the audit log belong to the client from day one. You stay on for policy changes, key rotation, new applications and the yearly review, as a member of their account or as a managed service.
The client’s account, not yours
Your engineers are members of the client’s account with the roles the client granted, and every action they take is attributed to them in the audit log.
What you get for joining
Migration checklist, reference configuration per jurisdiction, and the security documentation clients ask for.
Technical onboarding for your engineers, a test account to deploy against, and a named implementation certification.
Advisory and implementation work referred to you, with referral fees or resale margin per tier.
You introduce the client and stay advisory. Referral fee, no technical commitment, we run the deal.
You sell obstruo on your own paper and own the client relationship and billing. Margin on subscriptions.
You deploy and configure it, and optionally operate it as a managed service. Certification required, resale optional.
Start with one client deployment
Take one client through it end to end: keys into the vault, apps behind one endpoint, redaction and routing configured. Then pick a tier.