On-premise

The same platform, on your servers

Documents, rules, audit log and, if you wish, the models: everything stays inside your infrastructure. SaaS and self-hosting give you the same product; the choice is yours.

Why

When data must not leave

  • Nothing leaves your network

    Documents, conversations, indexes and the audit log live on your machines. Reachable from your internal network or VPN only.

  • The log stays with you

    The sealed ledger of decisions is stored and exported from your infrastructure. Your auditors read it without going through us.

  • Your models, up to air-gapped

    Your keys at the provider of your choice, or a model served locally through any OpenAI-compatible API: no outbound connection is then required.

  • Your policies, your pace

    Updates, backups and access follow your internal rules. We provide the images and the support, you keep control.

Architecture

What you install

One Docker Compose stack, the same services as our SaaS.

  1. PostgreSQL

    Organizations, users, rules, conversations and audit log.

  2. Qdrant

    Vector store for indexed documents, open source.

  3. Redis

    Queues and cache for indexing jobs.

  4. Docling

    Conversion of PDF, Office and images into structured text, on your machines.

  5. API, worker et interface GuardWeaver

    The engine, connectors, widget and administration, served from your network.

Prerequisites

What to plan for

A dedicated or virtual machine is enough to start. We size it together based on document volume and user count.

Operating system
Ubuntu 22.04 LTS or RHEL 8 and later
Runtime
Docker 24 and Docker Compose
Starting machine
8 CPUs, 16 GB memory, 200 GB SSD
Network
Outbound HTTPS to your model providers, or none in local mode
Local model, optional
Dedicated GPU, for operation without any outbound connection

Questions about self-hosting

Is the self-hosted product the same as the SaaS?
Yes. Same services, same features, same Platform and governed offers. Only the hosting changes: your servers instead of ours.
Do we need a dedicated operations team?
No. The install relies on Docker Compose and images we publish. We support the rollout and train your team for day-to-day operation.
Can it run with no outbound connection at all?
Yes, by serving models locally through an OpenAI-compatible API, for example with Ollama. A dedicated GPU is then required. Without that constraint, only calls to model providers go out, with your keys.
How is self-hosting billed?
On request, like the SaaS, based on the number of users and the scope. Inference stays with your model provider or on your machines, with no markup from us.

Want to see GuardWeaver at work in your company?

A thirty-minute demo with our team, on your own use cases: your rules, your tools, your teams.

A question first? Write to us.