Compliance that runs
inside your walls.
For companies whose security and privacy rules say evidence, code and AI systems stay on their own servers. Part of TryTrustable already runs in your environment, and the whole platform can be deployed on-premises for Enterprise customers.
Yes, in two ways. Today, the TryTrustable SDK and CI gate run inside your own pipeline and send only findings, with credentials redacted, never your source files. For companies that need the whole platform on their own servers, we offer on-premises deployment on the Enterprise plan: the platform runs in your cloud account or data centre, on a database you control, and our team deploys it with yours.
What already runs in your environment
Even on the hosted platform, your code stays with you. The SDK is a command-line tool and library that runs where your code already is. It reads your repository inside your pipeline, decides what fails, and reports the result. The platform receives findings, not files.
| What | Where it runs | What leaves your environment |
|---|---|---|
| Code scanning: secrets, static analysis, dependency vulnerabilities, policy checks | Your CI and developer machines, through the SDK | Each finding with the line it points to. Credentials in that line are redacted first |
| Merge and pre-push gate | Your pipeline | A pass or fail checkpoint for the commit |
| Consent discovery (where your code collects personal data or uses camera, microphone or location) | Your CI, as part of trytrustable sync | File paths, line numbers and the matched fragment. Never file contents |
| Cloud and identity checks: GitHub, AWS, Google Cloud, Okta, Google Workspace | Our platform, calling the provider's read-only API | Configuration results only, using read-only credentials you can revoke at any time |
Your source code is not uploaded. The SDK quotes the single line a finding points to so a person can see what matched, and strips credentials from it.
On-premises deployment: the whole platform on your servers
Some companies cannot send compliance evidence to any vendor's cloud: banks and insurers under data localisation rules, health companies, suppliers to government and defence, and AI companies whose models and training data are the business. For them, the whole platform can run in their own environment: the application, the evidence ledger, sealed reports, the auditor portal, consent records and the AI system register, on a PostgreSQL database they control.
Our team deploys the platform in your environment with yours: we scope the infrastructure, confirm which features need outbound access where you run, and deliver updates as new versions that you apply on your schedule. On-premises deployment is offered on the Enterprise plan. Tell us about your environment.
- Your database, your backups, your encryption keys
- Access for our team only when you grant it, for support you request
- The same SDK and CI gate as the hosted platform
- Sealed reports, verified against your own instance
For AI-first companies
If your models, prompts and training data are what you sell, your AI governance records are as sensitive as the models themselves. In the platform, the AI system register lists the AI systems you build and use, classifies each one under the EU AI Act, and maps the work to ISO 42001 and the NIST AI RMF. The SDK finds model providers in your dependencies and adds them to the register.
The platform's own AI features are optional and use the model provider key you configure. Security questionnaire answers are built from your controls and evidence without any model; when a model is used to word an answer, it receives only the cited snippets, never your whole dataset. On-premises, the register and every record behind it stay in your environment.
Hosted or on-premises: how to choose
Most companies start hosted and keep their code in their own pipeline through the SDK. Choose on-premises when a contract, a regulator or your own policy says the evidence itself may not leave your environment.
| Hosted | On-premises | |
|---|---|---|
| Where the platform runs | Google Cloud, Mumbai (India). We are expanding to Singapore, the US and the EU | Your own cloud account or data centre |
| Who holds the database | TryTrustable | You: your PostgreSQL, your backups, your encryption keys |
| Code and pipeline scanning | In your CI (the same SDK) | In your CI (the same SDK) |
| Updates | Continuous, by us | New versions delivered by us, applied on your schedule |
| Setup | Sign up and connect | Deployed by our team with yours |
| Plan | Starter, Growth, Scale or Enterprise (pricing) | Enterprise, agreed per customer |
The things people ask us
Can TryTrustable be deployed on our own servers?
Yes. On-premises deployment is offered on the Enterprise plan. Our team deploys the platform in your cloud account or data centre with yours, on a PostgreSQL database you control. Talk to us about your environment.
Does TryTrustable upload our source code?
No. The SDK runs in your pipeline and sends findings. Each finding quotes the single line it points to, with credentials redacted, so a person can see what matched. Consent discovery sends only file paths, line numbers and the matched fragment.
Can an on-premises deployment run with no internet access?
Tell us your constraints during scoping. Some features need outbound access by nature: cloud and identity checks call the provider's API, and cookie scans load your public website. We confirm which features work in your environment before you commit.
Who can see our data in an on-premises deployment?
Your team. The database, backups and keys are yours. Our team has access only when you grant it for support you request.
Where is the hosted platform?
On Google Cloud in Mumbai, India, today. We are expanding to Singapore, the US and the EU.
What does on-premises deployment cost?
It is offered on the Enterprise plan, priced per customer. See pricing for the hosted plans.
Keep your evidence where your policies say it lives.
Thirty minutes on your environment: what can run in your pipeline today, and what an on-premises deployment would look like for you.