How It Works
Inside ZEDEDA: How Edge Intelligence Runs at Scale
ZEDEDA delivers a unified platform to build, deploy, and operate edge intelligence across distributed environments. It unifies infrastructure provisioning, AI model and agent deployment, and lifecycle management across heterogeneous hardware, helping organizations avoid complexity or lock-in, while significantly reducing cost and latency compared to edge solutions that rely on cloud-based AI processing.
Built on open standards and a Zero Trust architecture, ZEDEDA provides the control, security, and repeatability required to run edge intelligence in real-world conditions.
ZEDEDA Architecture and Core Platform
The ZEDEDA Edge Intelligence Platform manages the full lifecycle of edge intelligence deployments, from device onboarding to AI workload orchestration and ongoing operations. It automatically reduces the complexity associated with matching AI models to the right inference engines and running them across a wide variety of edge AI hardware.
The platform establishes a consistent operational model across diverse edge hardware, allowing infrastructure, applications, models, and agents to be deployed and managed through a centralized control plane.
ZEDEDA connects to edge nodes running EVE-OS through a secure, outbound-only model—eliminating inbound ports and enforcing a Zero Trust posture by design.
The architecture is built to:
- Operate across heterogeneous edge hardware, from lightweight gateways to GPU-enabled systems
- Support edge intelligence workloads under real-world constraints, including limited bandwidth and intermittent connectivity
- Scale from initial deployments to large, distributed fleets using the same workflows
- Enforce Zero Trust across devices, workloads, and communication paths
How the Platform Works
ZEDEDA brings together orchestration, infrastructure, and AI lifecycle management into a single operational model designed for how edge intelligence actually runs in distributed environments.
The platform is built on three core pillars:
ZEDEDA Edge Intelligence Platform
The centralized control plane for deploying, managing, and securing edge intelligence at scale.
It governs access, enforces policy, and manages lifecycle operations across distributed edge clusters at global scale, with integrated edge-native services for updates, access control, and workload lifecycle management, including the inference engines, AI models, infrastructure services and AI agents that bring native MLOps and GitOps practices to the edge.
EVE-OS
A secure, open-source edge operating system purpose-built for edge intelligence.
It abstracts hardware complexity and provides a trusted foundation for running containers and virtual machines side by side on any edge device, with strong isolation, hardware-rooted identity, and no local user access. EVE-OS is supported on a wide range of hardware platforms, including x86 and ARM architectures. It comes with drivers and SDK support for a wide range of edge AI hardware accelerators to deliver the best in breed AI model inference performance.
ZEDEDA Edge Marketplace
A curated ecosystem of hardware vendors, infrastructure software partners, AI model providers, agent framework providers, edge AI silicon partners, edge intelligence solution partners and AI observability providers.
It enables interoperable, production-ready deployments without fragmentation or vendor lock-in.
Edge AI: From Model to Production in Minutes, Not Months
ZEDEDA operationalizes edge AI through a unified workflow that connects model development, deployment, and lifecycle management, without requiring custom infrastructure or heavy DevOps dependency.
The workflow follows four key stages:
Create a Project and Define Workloads
Administrators begin by creating a project, which may contain one or thousands of edge devices. Within the project, they define:
- Application and network policies
- Security and attestation requirements
- User access rights (RBAC)
- Expected hardware variations (GPU acceleration, LTE modules, etc.)
Using the ZEDEDA Marketplace, administrators select the applications and workloads to deploy. Marketplace manifests specify:
Source and Runtime Type
- Image locations
- Whether the workload runs as a container, VM, or Kubernetes service
Compute and Network Configuration
- vCPU and memory allocations
Network and firewall configurations
Instantiation Parameters
- Optional scripts or templates needed during instantiation
Hardware Requirements
- Direct-attach hardware (GPU, FPGA, USB, Serial)
Once reviewed, the configuration is applied to all current devices and automatically to any new devices that meet the project policies.
Order or Install EVE-Powered Devices
Organizations can order certified hardware with EVE-OS preinstalled, or they can install EVE themselves in minutes.
EVE installation includes:
- A secure identity workflow using a TPM-backed private key
- Creation of a hardware-rooted identity that cannot be cloned
- Initialization of mutually authenticated, outbound-only API connectivity to the ZEDEDA console
Once EVE is installed, the device is ready for zero-touch provisioning and can be shipped directly to the deployment location.
Plug In and Automatically Onboard — No IT Required
Upon connecting power and network, EVE initiates its measured boot and remote attestation workflow, which ensures:
- Software stack integrity
- Protection against firmware/rootkit modification
- Verification of hardware and boot components
- Enforcement of physical security (USB, Serial, and other ports isolated by default)
- Encryption of all communications (TLS)
Only after successful attestation does the device unlock encrypted storage and request its configuration from ZEDEDA Cloud.The device is then automatically assigned to the appropriate project and downloads its application manifests.
Instantiate Infrastructure, Runtimes, and Applications
With configuration in place, the edge node retrieves required images from the specified repositories—cloud or on-premises—and brings up system components accordingly.
Examples of services deployed on the node include:
- Windows or Linux VMs
- Native containers
- Kubernetes runtimes (K3s, Tanzu, MicroShift, etc.)
- IoT frameworks such as Azure IoT Edge
- Firewalls and SD-WAN endpoints
- Virtualized network functions (NFVs)
ZEDEDA’s deep API integrations can automatically configure controllers (firewall, SD-WAN, Azure services, Kubernetes platforms) for zero-touch service enablement.
ZEDEDA also supports segmented networks and offline environments through features like air-gap delivery and eventual consistency.
Monitor, Manage, and Update
From ZEDEDA's console, administrators can:
- Monitor device and application health
- Bulk deploy workloads across fleets
- Push software updates and security patches
- Adjust network interfaces and I/O assignments
- Add new applications or use cases dynamically
- Perform zero-touch onboarding of new devices
ZEDEDA provides rich operational visibility including:
- CPU, memory, disk, and network usage
- Detailed network flows
- Per-application performance
- Geographical device distribution
- Security posture and alerts
All updates to EVE-OS and applications are secure, fail-safe, and include automatic fallback to maintain uptime.
How ZEDEDA Works
ZEDEDA delivers a consistent and secure edge orchestration experience from device onboarding to full lifecycle management. The following steps illustrate how the platform works in practice.
Device Trust & Integrity
- Measured boot and remote attestation verify system integrity
- TPM-based identity prevents device spoofing and cloning
Data Protection
- Encryption at rest and in transit
- Model signing and encryption, with keys rooted in hardware security modules such as TPM
Access Control & Isolation
- Outbound-only communication model
- Lockdown of physical interfaces to prevent tampering
- Strong workload isolation across containers and virtual machines
Application & Deployment Security
- Cryptographic verification of system and application artifacts
- Distributed firewall enforcement at the workload level
- Secure, fail-safe updates with rollback protection
AI & Agent Security
- Built-in guardrails for agent behavior and execution
- Human-in-the-loop approval for selected workflows before autonomous actions
Security at Every Layer
ZEDEDA enforces Zero Trust across the full edge stack, protecting devices, workloads, data, and AI systems in environments where physical and network risks are inherent.
Threats addressed include:
- Unauthorized access and credential compromise
- Physical device tampering
- Network-based attacks on edge nodes
- Runtime and OS exploits
- Model theft, poisoning, and misuse
- Malicious or compromised agent interactions
To address these threats, ZEDEDA provides security controls at multiple layers:
Automation with APIs
ZEDEDA integrates into existing enterprise workflows through APIs and infrastructure-as-code support.
For advanced workflows, ZEDEDA supports Terraform and northbound APIs to automate the full lifecycle of edge intelligence, from provisioning to deployment and operations, while integrating with CI/CD systems, application controllers, orchestration platforms, and cloud environments.
Use cases include:
- Infrastructure and workload automation using Terraform
- Integration with cloud services for data pipelines and edge-to-cloud workflows
- SD-WAN and firewall integrations for secure connectivity
- Kubernetes ecosystem integrations for portable, cloud-native workload orchestration at the edge
- Custom lifecycle workflows built through northbound API integration with existing enterprise systems
Why ZEDEDA Works for the Edge
ZEDEDA is designed for the way edge intelligence operates in the real world, across distributed environments with constrained resources, limited connectivity, and no on-site IT.
Built for Distributed Environments
Operates reliably across air-gapped, low-bandwidth, and segmented networks
Vendor-Neutral by Design
Open architecture eliminates hardware and platform lock-in
Consistent Operational Model
Deploy and manage containers, virtual machines, models, and agents through a single workflow
Proven at Scale
Trusted to run mission-critical edge workloads across large, globally distributed fleets of edge nodes
Operationally Simple
Centralized control, policy-driven workflows, and GitOps keep distributed edge environments manageable for small teams