FAQs
Questions we are asked before the first call
If something here is unclear, or your situation is not covered, ask us directly — the answer comes from an engineer.
Data localization
For us it means three concrete things: the infrastructure is operated locally by a named organization, you can identify the facility your workloads run in, and the people who operate the platform are reachable and accountable under local arrangements.
It does not mean a badge. If a specific regulation applies to you, your legal and compliance teams define what it requires; we design and operate infrastructure to support that definition and give you the technical evidence.
No platform makes an organization compliant on its own. Compliance depends on how you classify data, what your applications do with it, your contracts, and your internal controls.
What we provide is infrastructure that can be designed around your requirements — placement of data, access control, audit logging, encryption, backup location and retention — together with documentation of how it is configured.
Platform
No. Hosting stops at the server. We provide cloud infrastructure, AI infrastructure and a managed application platform: Kubernetes, managed databases, object storage, GPU compute, delivery pipelines, monitoring, backup, and the engineering team that operates all of it.
Usually, yes. Many applications move as they are, onto virtual machines or containers, and are modernised later where it pays off. We would rather migrate something that works and improve it deliberately than start with a rewrite that takes a year.
Backups are designed per workload rather than applied uniformly, and recovery is tested rather than assumed:
- Agreed RPO and RTO for each application tier
- Encrypted backups with defined retention and isolation from the source environment
- Scheduled restore drills with recorded results
- A runbook written for whoever is on call, not for the person who built it
Yes. They run as containers on the same platform as everything else, which is what makes staging, rolling updates, backups and monitoring consistent rather than bespoke per application.
If an application only ships as a traditional server install, we will say so and host it on a virtual machine instead — under the same maintenance and support arrangement.
Managed services
Rarely, and usually not well. Most engagements are co-managed: your engineers keep product and application work, and we take the platform, delivery and operational load. Where an organization has no platform team at all, we can operate everything — but we will still want a technical owner on your side.
Coverage hours, first-response targets by severity, and the scope of what we maintain: platform and OS patching, backups and restore testing, certificate renewal, monitoring and incident response.
Response targets are set in your agreement rather than advertised loosely, because a target is only meaningful if the on-call rota behind it is real. Ask us for the current targets per tier.
Commercial
A conversation with an engineer, then a short assessment: what you run today, what has to stay local, what breaks most often, and what you need in the next twelve months. That produces an architecture and a scoped first phase — often a single workload — rather than a platform-wide programme.
You take your data and your configuration with you. The platform is built on open technologies — Kubernetes, PostgreSQL, S3-compatible storage, Terraform — specifically so that an exit is an engineering exercise rather than a renegotiation. Exit expectations are written into the engagement from the start.
Two separate invoices, and no margin hidden between them:
- Your cloud provider bills you directly for what you consume, at their price. The account stays in your name.
- Locara bills a management fee for designing, building and operating the environment.
Where a provider only bills through a reseller, we pass the invoice through at cost and show you the underlying charges. You always see what the infrastructure cost and what the operating cost.
AI
Many of them, yes: open-weight models for retrieval-augmented applications, classification, extraction and internal assistants run well on local GPU infrastructure, next to the data they need.
Some workloads still point to an external provider — where you need frontier-model capability or very large bursty training. We will tell you when that is the case, and help you design the boundary so the sensitive data stays where it must.
Security
Least privilege by default, individual named accounts rather than shared credentials, strong authentication, secrets held in a managed store with rotation, and audit logging of administrative actions. Standing access is kept to a minimum and reviewed on a schedule.
We do not claim certifications we have not obtained, and we would treat any provider that did with suspicion. The platform is designed and operated to support the controls those frameworks test — hardening, access control, logging, change management, backup and recovery — and we provide the technical evidence your auditors ask for. Ask us directly about our current status and roadmap.
Still deciding whether this fits?
Send us the constraint you are stuck on. If we are the wrong answer, we will say so.