Where the system runs is the first security decision. The platform ships as containers with CI/CD delivery and Caddy TLS, and can run entirely inside your own boundary. Below are the deployment models, mapped to who each fits and what to know — consistent with the self-hosted / managed / custom tiers on the Pricing section. No per-seat fees. Review the underlying controls on the Security page.
Self-hosted keeps the full platform and your data inside your own infrastructure.
Managed gives you fully-operated infrastructure with monitoring and support.
Private cloud / VPC and hybrid place the system inside your chosen environment.
White-label and embedded / API put governed agents behind your own brand or app.
Each model carries the same governed-autonomy controls — RBAC, signed agent-to-agent calls, skill allowlists, sandboxed non-root execution, hash-chained audit logs, and a supreme kill-switch. What changes is where it runs and who operates it.
The full platform on your infrastructure, with all capabilities and your data inside your own boundary. The default choice when data residency and isolation are non-negotiable.
Fully managed operations with monitoring, custom skills, and support, on infrastructure we run for you. The fastest path to value when you would rather not operate it yourself.
The platform deployed inside your own cloud account or virtual private cloud, so it runs in an environment your team already governs and monitors.
A split topology — sensitive components and data stay in your boundary while other parts run managed — so you draw the line where your risk posture requires it.
Governed agents delivered under your own brand. The capability is available on the Managed tier and scoped further under Custom.
Drive governed agents from your own application through the platform's REST API, embedding agent workflows into a product you already ship.
Tell us your data residency, risk controls, and operating constraints — we will map you to the model that fits.