Deployment

Runs in your infrastructure. Or in your cloud. Or we run it for you.

Self-hosted is how most of our customers deploy, and it is what the platform was built around - air-gapped, local LLM, nothing leaving the network. If you would rather not run it yourself, the same engine is available in your own cloud account or as a dedicated instance we operate.

Three ways to run it

Same engine. Same evidence. Same results.

The choice is where it runs, not what you get. Every edition, every scanner and every feature is identical across all three - there is no cut-down deployment.

Self-hosted

Recommended

Your infrastructure, your network, your rules

Docker Compose or Kubernetes inside your own perimeter. Nothing calls home, the LLM runs locally, and the platform works with no internet route at all. This is what regulated buyers deploy, and it is the configuration the product was designed around.

  • Air-gapped capable
  • Local LLM, no external inference
  • Your own backups and keys
  • Perpetual licence available

Your cloud

Also supported

Same install, running in your own cloud account

The identical deployment inside your AWS, Azure or GCP subscription. The data plane stays in infrastructure you own and bill for, so residency and network policy remain yours, while you skip running hardware.

  • Your account, your VPC
  • Data residency stays yours
  • Terraform-friendly
  • Scales with your own quota

Managed by apPosture

Also supported

A dedicated instance we operate for you

Single-tenant: your own instance, your own database, operated and upgraded by our team. For teams that want the platform without owning the runbook. It is a dedicated deployment, not a shared multi-tenant pool.

  • Single-tenant, never shared
  • We handle upgrades and monitoring
  • Region of your choice
  • Move to self-hosted whenever you want
Data boundary

Where your code and findings actually sit

The honest version of the question. In the first two, nothing crosses your perimeter - including the AI, which runs locally. In managed, your code reaches an instance we operate, and that is the trade you are making for not running it yourself.

Side by side

What actually differs

Four rows decide this for most teams: where the data sits, who patches it, who holds the keys, and whether you need to operate without an internet route.

Self-hostedYour cloudManaged
Where the code and findings liveYour networkYour cloud accountDedicated instance we run
Air-gapped operationYesIf your account allows itNo
Who applies upgradesYouYouWe do
Who holds the encryption keysYouYouYou, escrowed with us
Infrastructure to runYoursYoursNone
Time to first scanAbout 10 minutesAbout 10 minutesSame day
Feature setCompleteCompleteComplete

Managed is a dedicated single-tenant instance. We do not operate a shared multi-tenant pool, and there is no free metered tier - the trial is a full 30-day proof of concept, in whichever model you plan to buy.

Choosing

Which one is yours

Pick self-hosted if

  • You are in finance, government, defence or healthcare
  • Source code cannot leave your network under any circumstances
  • You have data-residency or sovereignty obligations
  • Some environments have no internet route at all

Pick your cloud if

  • Your estate is already in AWS, Azure or GCP
  • You want the data plane in an account you own and audit
  • You would rather not run hardware
  • Your platform team deploys with Terraform

Pick managed if

  • You want security outcomes, not another runbook
  • You have no platform team to spare
  • You need to be scanning this week
  • You may move it in-house later

Moving between them is a supported path, not a migration project. Teams that start managed and later bring it in-house keep their findings, history and evidence - the deployment changes, the data does not.

apPosture

Not sure which fits? We will tell you straight.

A 30-minute call, your constraints, an honest recommendation - including when self-hosting is more work than it is worth for you.