





In air-gapped mode, no internet access is required after initial deployment. Connector logos and static assets are bundled in the image. Kubernetes image pulls happen from your internal registry. In VPC mode, there may be outbound calls for license validation and update channels — these are configurable and can be routed through your egress controls.
Yes. Docker Compose packaging is available for development, testing, and lower-scale deployments. For production at enterprise scale, Kubernetes with Helm is recommended.
Nothing on our infrastructure. In on-prem mode, all data — user records, sessions, OAuth tokens, access keys — is stored in your Postgres instance, inside your deployment. Scalekit has no database access and no visibility into your stored data.
Licensing is per deployment. Each isolated customer instance gets its own license key. In air-gapped mode, validation is fully offline — no activation call required. Contact us to discuss volume pricing for multi-tenant deployment scenarios.
Each agent authenticates independently through the token vault. Credentials are scoped per agent, per user, per connector — there is no shared credential pool. The gateway enforces scope isolation at call time, so a downstream agent in a chain cannot escalate to credentials it wasn't explicitly granted.
No. In an on-prem deployment, no data reaches Scalekit infrastructure. We are not in the data processing chain. Scalekit is not listed as a sub-processor for on-prem customers. Under HIPAA, we can sign a BAA as a business associate; under GDPR, there is no data processing role to document.