On-premises

Compliance that runs
inside your walls.

For companies whose security and privacy rules say evidence, code and AI systems stay on their own servers. Part of TryTrustable already runs in your environment, and the whole platform can be deployed on-premises for Enterprise customers.

SDK runs in your CICredentials redacted before uploadRead-only connectorsOn-premises deployment
Short answer

Yes, in two ways. Today, the TryTrustable SDK and CI gate run inside your own pipeline and send only findings, with credentials redacted, never your source files. For companies that need the whole platform on their own servers, we offer on-premises deployment on the Enterprise plan: the platform runs in your cloud account or data centre, on a database you control, and our team deploys it with yours.

01

What already runs in your environment

Even on the hosted platform, your code stays with you. The SDK is a command-line tool and library that runs where your code already is. It reads your repository inside your pipeline, decides what fails, and reports the result. The platform receives findings, not files.

WhatWhere it runsWhat leaves your environment
Code scanning: secrets, static analysis, dependency vulnerabilities, policy checksYour CI and developer machines, through the SDKEach finding with the line it points to. Credentials in that line are redacted first
Merge and pre-push gateYour pipelineA pass or fail checkpoint for the commit
Consent discovery (where your code collects personal data or uses camera, microphone or location)Your CI, as part of trytrustable syncFile paths, line numbers and the matched fragment. Never file contents
Cloud and identity checks: GitHub, AWS, Google Cloud, Okta, Google WorkspaceOur platform, calling the provider's read-only APIConfiguration results only, using read-only credentials you can revoke at any time

Your source code is not uploaded. The SDK quotes the single line a finding points to so a person can see what matched, and strips credentials from it.

02

On-premises deployment: the whole platform on your servers

Some companies cannot send compliance evidence to any vendor's cloud: banks and insurers under data localisation rules, health companies, suppliers to government and defence, and AI companies whose models and training data are the business. For them, the whole platform can run in their own environment: the application, the evidence ledger, sealed reports, the auditor portal, consent records and the AI system register, on a PostgreSQL database they control.

Our team deploys the platform in your environment with yours: we scope the infrastructure, confirm which features need outbound access where you run, and deliver updates as new versions that you apply on your schedule. On-premises deployment is offered on the Enterprise plan. Tell us about your environment.

  • Your database, your backups, your encryption keys
  • Access for our team only when you grant it, for support you request
  • The same SDK and CI gate as the hosted platform
  • Sealed reports, verified against your own instance
03

For AI-first companies

If your models, prompts and training data are what you sell, your AI governance records are as sensitive as the models themselves. In the platform, the AI system register lists the AI systems you build and use, classifies each one under the EU AI Act, and maps the work to ISO 42001 and the NIST AI RMF. The SDK finds model providers in your dependencies and adds them to the register.

The platform's own AI features are optional and use the model provider key you configure. Security questionnaire answers are built from your controls and evidence without any model; when a model is used to word an answer, it receives only the cited snippets, never your whole dataset. On-premises, the register and every record behind it stay in your environment.

04

Hosted or on-premises: how to choose

Most companies start hosted and keep their code in their own pipeline through the SDK. Choose on-premises when a contract, a regulator or your own policy says the evidence itself may not leave your environment.

HostedOn-premises
Where the platform runsGoogle Cloud, Mumbai (India). We are expanding to Singapore, the US and the EUYour own cloud account or data centre
Who holds the databaseTryTrustableYou: your PostgreSQL, your backups, your encryption keys
Code and pipeline scanningIn your CI (the same SDK)In your CI (the same SDK)
UpdatesContinuous, by usNew versions delivered by us, applied on your schedule
SetupSign up and connectDeployed by our team with yours
PlanStarter, Growth, Scale or Enterprise (pricing)Enterprise, agreed per customer
Questions

The things people ask us

Can TryTrustable be deployed on our own servers?

Yes. On-premises deployment is offered on the Enterprise plan. Our team deploys the platform in your cloud account or data centre with yours, on a PostgreSQL database you control. Talk to us about your environment.

Does TryTrustable upload our source code?

No. The SDK runs in your pipeline and sends findings. Each finding quotes the single line it points to, with credentials redacted, so a person can see what matched. Consent discovery sends only file paths, line numbers and the matched fragment.

Can an on-premises deployment run with no internet access?

Tell us your constraints during scoping. Some features need outbound access by nature: cloud and identity checks call the provider's API, and cookie scans load your public website. We confirm which features work in your environment before you commit.

Who can see our data in an on-premises deployment?

Your team. The database, backups and keys are yours. Our team has access only when you grant it for support you request.

Where is the hosted platform?

On Google Cloud in Mumbai, India, today. We are expanding to Singapore, the US and the EU.

What does on-premises deployment cost?

It is offered on the Enterprise plan, priced per customer. See pricing for the hosted plans.

Book a walkthrough

Keep your evidence where your policies say it lives.

Thirty minutes on your environment: what can run in your pipeline today, and what an on-premises deployment would look like for you.