Bring your own cloud sounds like the end of the lock-in conversation. Your AWS account, your VPC, your data residency, your committed-use discounts — with Northflank's control plane sitting on top doing the deploying, scaling, and observing. No shared tenancy, no noisy neighbors, no data ever leaving infrastructure you pay for directly.
Here is the part the pitch does not put in bold: the meter comes with the control plane. On Northflank, compute bills at $0.01667 per vCPU-hour and $0.00833 per GB-hour, timed by the second — and on a BYOC cluster, that platform meter runs on top of whatever your cloud provider already charges for the same cores and gigabytes. You moved the workloads into your account. You did not remove the second bill. The verdict up front, with receipts below:
| Footprint: API + worker + Postgres, ~4 vCPU / 8 GB, 24/7 | Monthly total |
|---|---|
| Northflank hosted (platform meter only) | ~$97/mo + storage/egress |
| Northflank BYOC (AWS bill + platform meter) | ~$219/mo (two meters, one workload) |
| Same footprint on an owned Hetzner box | ~$13/mo flat, 20 TB traffic included |
Read that middle row twice, because it is the whole argument in one number. BYOC decouples where your workloads run from who meters them — and then keeps metering them anyway. The rest of this post is the line-by-line math behind each cell, an honest accounting of what the meter buys you, the bill no invoice shows (control-plane ownership), and when BYOC is still the right call.
What BYOC actually is
Northflank's Bring-Your-Own-Cloud model attaches your own Kubernetes capacity — EKS on AWS, GKE on GCP, AKS on Azure, plus Oracle, CoreWeave, Civo, on-premises, or bare metal — to Northflank's hosted control plane (Northflank's own BYOC writeups describe it as running services inside your own cloud accounts while managing deployments through their dashboard, API, or CI/CD). BYOC is available self-serve on pay-as-you-go plans with no sales process, and the company backs it with real enterprise posture: SOC 2 Type 2, HIPAA compliance with signed BAAs, and a forward-deployed control plane option for regulated customers.
The model is genuinely good at the things it claims. Your data never leaves your VPC, which is why regulated teams and AI-sandbox vendors pick it — Qovery's 2026 agent-infrastructure roundup puts it plainly: with BYOC, "the vendor runs the control plane while your workloads and data run in an account or cluster you already operate," and for agents touching customer data that shape is "usually the only viable option, not an enterprise upsell." Northflank's own case study — cto.new migrating its entire sandbox infrastructure in two days after EC2 metal instances made scaling costs unpredictable — shows the model working as designed: thousands of daily deployments of untrusted code, per-second billing, data in the customer's account.
And investors bought the thesis. Northflank raised $22.3 million — a $16 million Series A led by Bain Capital Ventures plus a $6.3 million seed led by Vertex Ventures US (announced November 2024) — to sell exactly this middle position: your cloud, managed for you. Not a hosted PaaS, not raw Kubernetes. The control plane as the product.
That last sentence is the one to hold onto, because it cuts both ways.
The worked math: one workload, three bills
Assumptions stated plainly so you can check the arithmetic: a small production topology — API, background worker, Postgres — sized at 4 vCPUs and 8 GB of RAM, running 24/7 (730 hours/month). Northflank at its published pay-as-you-go rates of $0.01667/vCPU-hour and $0.00833/GB-hour. AWS on-demand for the underlying BYOC capacity (two t3.large equivalents at $0.0832/hour each). Hetzner at community-reported cloud pricing for a 4-vCPU/8-GB box (~€11–12/month, ~$13, 20 TB of included traffic — canonical numbers at hetzner.com/cloud).
Bill 1: Northflank hosted. CPU: 4 × $0.01667 × 730 = $48.68. RAM: 8 × $0.00833 × 730 = $48.65. Total: ~$97/mo, before SSD storage ($0.15/GB-month) and egress ($0.06/GB). One meter, and you can see exactly what it measures.
Bill 2: Northflank BYOC on AWS. The cloud bill first: 2 × $0.0832 × 730 = ~$121/mo for the underlying instances. Then the platform meter on the same 4 vCPU / 8 GB: ~$97/mo, same arithmetic as Bill 1 — because as Railway's own Northflank comparison notes, bringing your own cluster adds Northflank platform fees on top of your cloud provider's bill. Total: ~$219/mo. Two meters, one workload, and the second meter charges you for cores you already rented.
Bill 3: owned Hetzner box. ~$13/mo flat. The API, the worker, Postgres, and up to 20 TB of transfer all fit inside the sticker price. No per-second meter, no per-GB RAM line, no egress overage at any volume a small production app will reach.
That is roughly a 17x spread between BYOC-on-AWS and owned hardware at steady state — and now the mandatory sensitivity analysis, because single-point comparisons lie by omission. The ranking flips on one variable: utilization.
At 10% average utilization — bursty previews, a staging fleet asleep most nights — Northflank's per-second meter burns ~$9.70/mo on the platform side, and the whole argument above collapses: the meter is cheaper than any flat box, because you are not paying for idle. That is precisely the workload BYOC and per-second billing were built for, and pretending otherwise would be dishonest.
The crossover sits somewhere around 30–40% sustained utilization for the platform-meter component, and much sooner once the underlying cloud bill is hourly rather than usage-proportioned. Steady-state production — the API that serves traffic at 3 AM, the worker that never sleeps, the database that is always on — is where stacked meters compound and flat hardware wins by an order of magnitude. Know which workload you are pricing before you pick a side.
What the meter buys: a fair accounting
None of the above means the $97 platform line is fraud. It pays for a real bundle, and pricing the bundle at zero — the way lazy self-hosting math does — is how teams end up surprised by their own ops load. Concretely, the Northflank meter buys:
- Managed CI/CD and preview environments per pull request, with build, deploy, and rollback behind one dashboard and API instead of a Jenkinsfile somebody owns.
- Managed databases (Postgres and friends) with backups, scaling, and failover handled by the vendor rather than by whoever drew the short straw on your team.
- MicroVM-grade isolation — Kata Containers, Firecracker, or gVisor depending on workload — which is genuinely expensive engineering to build yourself and matters the moment you run untrusted code like agent sandboxes.
- Observability, log retention, and secret management wired in by default, plus the SOC 2 / HIPAA posture that lets regulated teams attest to their setup without building the evidence trail from scratch.
The honest price of the owned box is therefore $13 plus the ops labor: somebody patches the OS, upgrades Kubernetes, rotates the certs, tests the Postgres backups, and gets paged. For a team with no platform engineer, that labor dwarfs every number in the table above, and BYOC is rationally worth it — you keep data residency and your cloud discounts while renting the ops team by the vCPU-hour. The mistake is not paying for operations. The mistake is believing BYOC removed the vendor from the architecture, when it only moved the vendor one layer up.
The bill the invoice can't show: who owns the control plane
Money is the visible half of "someone else's bill." The other half is control, and it is entirely absent from the invoice. In the BYOC model, Northflank's hosted control plane is the single point that provisions your clusters, runs your CI/CD, holds your deployment credentials, meters your usage, and gates your dashboard and API access. Your containers keep running in your account if that control plane has a bad day — the data plane survives — but you cannot deploy, scale, roll back, or manage anything until it comes back. That is not a hypothetical asymmetry; it is the architecture, and it applies equally to billing disputes, pricing changes, and the day you decide to leave.
Note what exists and what doesn't. A forward-deployed control plane — Northflank's plane running inside your boundary — exists, but it is an enterprise offering, not part of the self-serve BYOC story most teams actually buy. On every self-serve tier, "your cloud, our control plane" means the kill switch for your deployment pipeline lives in someone else's incident-response channel. BYOC decoupled the data plane beautifully: residency, noisy-neighbor isolation, your cloud discounts all check out. It did not decouple the control plane at all — and the control plane is the part that decides whether you can ship on a Friday afternoon.
Contrast that with a platform whose control plane you also own outright: Cluster-API-managed machines on hardware you rent or own, provisioned by controllers running on your own management cluster. There is no second company in the deploy path, no platform meter to stack, no dashboard that can lock you out of your own fleet. The tradeoff is the one from the previous section — you operate it — but the failure modes are yours: your outage to fix, your roadmap to set, nobody else's pricing page to watch.
When BYOC wins, when owning wins
BYOC is the right call when the control-plane bundle is worth more than its meter: regulated data that must stay in your VPC but a team too small to run Kubernetes well, bursty sandbox fleets where per-second billing beats flat hardware, cloud-committed spend you want your discounts applied against, or a migration in progress where the team needs PaaS ergonomics on infrastructure they already pay for. These are common, legitimate shapes — which is exactly why venture capital funded the middle position.
Owning wins when the workload is steady, the topology is boring, and the meter has become a growth tax: a 24/7 API plus worker plus database whose BYOC total runs ~17x the flat-hardware number, where the ops burden is one well-understood cluster rather than a fleet, and where "who can turn off our deploys" has an uncomfortable answer involving a vendor status page. That crossover is not a feeling; it is the arithmetic in the table at the top, recomputed with your utilization and your egress.
The question BYOC asks — whose account does the compute live in? — turned out to be the easy half of independence. The harder half is whose meter, and whose control plane, sits between you and a deploy. Answer that one with numbers, not branding, and the bill stops being someone else's either way.
Bex.co is the open-source, AI-native Render alternative — push a git repo, get a running HTTPS service on machines you own, with the control plane included instead of metered on top. Star the repo on GitHub or deploy your first app today.



