Run it inside your own perimeter

The same product, deployed in your VPC. No grant, no token and no identity leaves your network. Licensed per monitored identity, with a term you renew rather than a subscription we can switch off.

What it needs

Compute

Four cores and 8 GB of memory for up to 2,500 monitored identities. Scanning is I/O bound, not CPU bound.

Storage

PostgreSQL 15 or later. About 400 MB per 1,000 identities per year of history.

Network

Outbound HTTPS to your providers only. No inbound rule, and no route to us unless you enable the daily licence check.

Identity

Any SAML or OIDC provider for sign-in. Local passwords work until you configure one.

Mail

An SMTP relay for alerts and password resets. The product runs without one, but sends nothing.

Air-gapped

Supported. The licence is read from a signed file and no call is ever attempted.

What we can and cannot see

In self-hosted mode we hold your licence key, your deployment name, and, if you leave the daily check on, a count of monitored identities and a version string. That is the whole list.

We never hold a provider token, a grant, a subject address, a score, an alert or a member account. Those exist only in your database. If you turn the daily check off, we hold nothing at all and cannot warn you before a term lapses.

The comparison cohort on Benchmark needs aggregate counters from a population, so it is unavailable in self-hosted mode unless you opt in to contributing. Opting out costs you the comparison, not the product.

Before you commit

Both directions, once per term. The inventory is exported as signed JSON and re-imported; scores are recomputed on the first scan rather than carried over, so history restarts at the migration date.

Start with the guide, not the download

The install guide is twenty minutes of reading and saves an afternoon. It covers the licence, the database, the identity provider and the first scan.