The enterprise platform for agentic AI
With Cenna Apex, enterprises can build, deploy, and govern custom agentic apps faster — with full control.
Complete, working applications for Legal, IT, HR, and Support. Your developers customize the source code in the tools they already use. You deploy into your own AWS or Google Cloud account — and see every model call and every dollar from one console.
Your cloud. Your code. Your control.
Built on
Available through AWS Marketplace, so Cenna draws down your existing AWS commitment.
The problem
Every team wants an agentic AI application. Legal, IT, HR, Support — all of them, right now.
Today there are two ways to get one. Build it in-house, and each team spends months on the same foundation before the first agent runs: login, integrations, deployment, audit trails. Or buy a vertical AI product, and pay per seat forever while your contracts, your tickets, and your employee records sit in someone else's cloud.
Cenna is the third way.
S1The product
A complete application on day one
Not a blank canvas, and not a chatbot bolted onto your data. Every Cenna application arrives with the interface, agents, workflows, and permissions the work actually requires — then you make it yours.

S2Why Cenna
Speed of buying. Control of building.
Buying a vertical AI product gets you there fast and costs you control. Building in-house keeps control and costs you a year. Cenna Apex is the accelerator that gives you both.
| Comparison | Vertical AI product | Build it in-house | Cenna Apex |
|---|---|---|---|
| Speed to production | |||
| Time to a working application | Weeks | Quarters | Days |
| Infrastructure to get there | The vendor's problem | VPC, IAM, secrets, CI/CD, and monitoring, all from scratch | One standard path, already configured |
| Who has to build it | Nobody — you rent it | A platform team you have to hire: DevOps, SRE, security | The developers you already have |
| Who runs it at 3am | The vendor | Your on-call rotation | Cenna operates the platform, you own the application |
| Keeping it current | Wait for the vendor's roadmap | Your team owns every upgrade, forever | Cenna ships platform updates, you keep the code |
| Cost control | |||
| What you can see | One line on an invoice | Whatever you built the metering for | Spend by app, task, and user on day one |
| Stopping tokenmaxxing | Not your call | Budgets, caps, and alerts are yours to build | Budgets, alerts, and hard caps included |
| The second and third application | Another contract, another seat count | Most of the build starts over | Same platform, new application |
| Control & security | |||
| Who owns the source code | The vendor | You | You |
| Where your data lives | The vendor's cloud | Your cloud | Your cloud |
| Which models teams can call | Whatever the vendor picked | You build the policy layer | One approved list, enforced everywhere |
| Connecting your systems | Only the vendor's connectors | Every integration hand-wired and scoped by you | Declared with explicit scopes in config |
| Audit trail | The vendor's logs, on request | You build it | Every agent run traced and priced |
Cenna Apex is an accelerator, not another dependency. The foundation every agentic application needs — identity, integrations, deployment, spend controls, audit — is already built and already running, so reaching production does not start with staffing a platform team. You get there in days instead of quarters, and the application itself stays entirely yours.
S3How it works
From catalog to production in four steps
The same path for every application, whether you start from one of ours or bring code you already have.
- 01
Choose
App StoreContract HubDeployIT HelpdeskDeployHR OnboardingDeployPick an application from the Cenna store, or point Cenna at a repository your team already owns.
- 02
Customize
def review(doc): clauses = extract(doc) return playbook.check(clauses)
Your developers change the agents, workflows, and interface in your own repo. Integrations are declared with explicit scopes, not hand-wired.
- 03
Deploy
→ cenna deploy contract-hub✓ aws_vpc · 3 subnets✓ aws_ecs · 3 tasks✓ tls cert · issued✓ Live · contract-hub.acme.ioCenna provisions networking, identity, secrets, and monitoring inside your AWS or Google Cloud account.
- 04
Operate
Fleet health4,821Users$3.4kSpend98%HealthyWatch spend, model calls, agent traces, and application health for the whole fleet from one dashboard.
S4Applications
Start with the application your business needs
Each application ships with the interface, the agents, the workflows, and the role-based permissions the job actually needs. Launch the foundation in days, and spend your engineering time only on what makes your business different.

Agentic ITSM
Agents triage incoming tickets, search your knowledge base, and close routine requests without a person in the loop.
- Ticket triage and routing
- Access requests
- Password and account resets
- Software installs and licences
- Knowledge base answers

Agentic HR
Agents run the employee lifecycle end to end — provisioning on day one, revoking on the last day, and handling the requests in between without anyone learning your HRIS.
- Employee onboarding and provisioning
- Offboarding and access revocation
- Time off and leave requests
- Policy and benefits questions
- Employee data and role changes
- Compensation requests
- Employment verification letters

Agentic Legal
Agents review incoming contracts against your playbook, flag off-standard clauses, draft the redline, and track obligations after signature.
- Contract review against your playbook
- Redline drafting
- Obligation tracking after signature
- Vendor and third-party risk review
- Legal intake and triage

Customer Support
Agents research the customer's history across your systems, draft the response, and take the follow-up action.
- Case research across systems
- Response drafting
- Refunds and replacements
- Escalation routing
- Post-resolution follow-up

Bring Your Own App
Already built something? Deploy it on Cenna and it gets the same identity, cloud deployment, and spend governance as a native application.
S5Developers
Build in Cursor or Claude. Ship on Cenna.
The Cenna App SDK carries the parts every enterprise application needs — authentication, interface, agent orchestration, integrations, workflows, deployment. Your team writes only the logic that is specific to your business.
Customize the business logic. Reuse everything else.
Talk to us about the SDK →// Your team writes only this.
import { defineApp, sso } from '@cenna/app-sdk';
import { intake, review, obligations } from './agents';
export default defineApp({
auth: sso('okta'),
agents: [intake, review, obligations],
integrations: ['salesforce', 'docusign', 'slack'],
deploy: { cloud: 'aws', region: 'us-east-1' },
});S6Deployment
Your cloud, without the three-month infrastructure project
One standard path to production on AWS or Google Cloud. Networking, identity, secrets, CI/CD, and monitoring come configured. You approve the account — Cenna handles the rest.
AWS · Google Cloud · Azure (coming soon)

S7Model spend
See every AI dollar before the invoice arrives
Tokenmaxxing turned AI spend into a number nobody could predict. Cenna makes it a line item: token spend by application, task, user, and model, budgets and alerts on every app, and an approved-model list enforced everywhere.
Token spend by app, task, user, and model · Budgets and alerts · Approved model list
- Claude Sonnet 5Allowed
- Claude Haiku 4.5Allowed
- GPT-5.2Allowed
- GPT-5.2 miniAllowed
- gpt-4oBlocked
Example data shown for illustration.
Every agent run is traced and priced on its own — a clause analyzer at 63 spans and $0.92, a redline drafter at 38 spans and $0.64. When spend moves, you can name the task that moved it.
S8Cloud spend
The other half of the bill, in the same console
Model tokens are only part of what an agentic application costs. Cenna reports cloud spend by application, target, and service — Fargate, Postgres, load balancers, cache, storage — right next to the AI spend it belongs with. The true cost of an application is one number, not two dashboards and a spreadsheet.
Cloud spend by app, target, and service · Budget pacing per application · AI and cloud cost side by side
- Contract Hub$2,316$1,842 AI · $474 cloud
- Vendor Risk$1,150$964 AI · $186 cloud
- HR Onboarding$684$486 AI · $198 cloud
- IT Helpdesk$252$118 AI · $134 cloud
Example data shown for illustration.
S9Data, security & governance
Controls your reviewers can verify
Cenna never becomes a new place your data lives. Access follows the identity provider you already run, every integration declares what it is allowed to touch, and every agent run leaves a trace you own.

Data residency
Applications and data stay in your cloud account and region. Nothing is copied to Cenna.
Enterprise identity
Access follows your existing SSO and IAM, with role-based permissions per application.
Model governance
Each application carries its own allowed-model list, and a call to anything off it is refused.
Integration scopes
Every connection declares exactly what it may do — SharePoint read, Slack write, DocuSign signature — and nothing runs outside that grant.
Agent traces
Every agent run is recorded as a trace with its spans and its cost, so any action can be replayed and any dollar explained.
Emergency controls
Pause an agent, revoke an integration, or stop an application without waiting on a support ticket.
SOC 2 Type II attested. Reports and policies live in our Trust Center. Because applications run in your account, Cenna stays inside your existing compliance boundary.
View Trust CenterS10FAQ
Frequently asked questions
What exactly do we have at the end of the first week?
A working application running in your own cloud account, its source code in a repository you own, and the console tracking its health, spend, and agent activity. Not a sandbox or a pilot environment — the same deployment you keep.
Who has to be in the room to deploy it?
Someone who can approve a cloud account or project, someone who administers your identity provider, and a developer. Cenna provisions the networking, IAM, secrets, CI/CD, and monitoring on a standard path, so there is no platform team to staff before you start.
What can the agents actually reach in our systems?
Only what you grant. Every integration declares an explicit scope — SharePoint Sites.Read.All, Slack chat:write, DocuSign signature — and those scopes are listed per application in the console. An agent cannot act outside its grant, and revoking one takes effect immediately.
What happens when an agent gets something wrong?
Every run is recorded as a trace you can open: the spans it executed, the calls it made, and what it cost. You can replay the run to see what the agent decided, pause the agent, or revoke its integrations yourself — none of it requires a support ticket.
How do we stop an agent from running up an enormous bill?
Budgets and hard caps per application, plus a fleet cap. Spend is metered by application, task, user, and model as it happens, and pace alerts fire before month end. Tokenmaxxing is a governance failure, and the controls for it ship with the platform.
Which models can our teams use?
The ones you approve, chosen per application across providers. The approved list is enforced centrally, so a team cannot quietly reach for something off it — a blocked call surfaces as an alert instead of a line on next month's invoice.
Does this replace ServiceNow or Salesforce?
No. Cenna applications work alongside your systems of record, reading and writing through scoped integrations. Your data stays where the business already keeps it.
What does customization actually take?
The application arrives complete, so your developers change business logic and configuration instead of building a foundation. The work is TypeScript in your own repository, in Cursor, Claude, or any IDE — no proprietary editor and no new skill set to hire for.
You are an early-stage company. What happens to us if Cenna does not make it?
Your applications keep running. The source code sits in your repository and the deployment sits in your cloud account, so neither depends on Cenna being reachable. You are buying an accelerator, not a runtime you can be evicted from.
And if we simply want an application gone?
Uninstalling it tears down the cloud resources it created and snapshots the data for thirty days before deletion. Removing an application is a normal operation in the console, not a support escalation.
Start with a working application. Not a blank page.
See a complete Cenna application customized and deployed into a cloud account, end to end, in a thirty-minute walkthrough.
Get a DemoBuilt for speed. Engineered for control.
