Self-Hosted Deployment

Deploy auth and tool-calling
in your infrastructure

VPC, customer on-prem, or fully air-gapped. Your tokens and data never leave your infrastructure.

Three deployment modes.
VPC, customer infra, or air-gapped.

Pick the deployment mode that best suites your infrastructure allows.
Mode 1
VPC deployment
Runs inside your own AWS, GCP, or Azure VPC. 
Customer data never leaves your cloud.
Mode 2
Customer infra deployment
Deployed into your customer's infrastructure,
fully isolated. You hold the keys 
and control upgrades
Mode 3
Air-gapped deployment
No outbound calls to Scalekit. Offline license validation, images from your registry, built for classified networks.
Tell us your deployment context
Your infra, instance count, and compliance requirements — HIPAA, CMMC, or your own policy.
WHO SELF-HOSTS SCALEKIT

Your customers require auth credentials
to stay on-prem

That includes OAuth tokens, API keys, and every tool-call credential your agents use.
Healthcare & FHIR
Connect to FHIR-compliant health tools without PHI leaving your boundary. HIPAA-compatible deployment. BAA available.
Defense & DoD
One isolated instance per customer. Air-gapped for SCIF networks, CMMC-aligned, nothing leaves.
Financial services
Data residency is in the contract, not the security questionnaire. Tokens on an outside vendor stall the deal.
Government & public sector
Sensitive workloads under strict residency rules. Runs inside the boundary or it does not run.
Token Vault Architecture

Credentials never touch your agent.
Not in code, not in context.

Tokens live in a vault inside your deployment. The gateway injects the credential at call time, so the agent calls the tool, never the token.

Isolated token vault

Encrypted at rest, isolated per tenant. Never in your agent code, your logs, or the model context.

Bring your own KMS

Encryption keys stay in your key management system. Connect AWS KMS, Google Cloud KMS, or Azure Key Vault — we encrypt the token vault with your keys, and we never hold them.
Self-Hosting Guarantees

If it's air-gapped,
it's actually air-gapped.

No data, logs, metrics, or telemetry ever reaches Scalekit infrastructure in an air-gapped deployment.
Guarantee 01
No data leaves your deployment
Credentials, OAuth tokens, session data, and user records are stored and processed entirely within your deployment. No Scalekit server is in the data path.
Guarantee 02
No telemetry by default
Usage metrics stay in your observability stack, not ours. There is no default outbound metrics channel.
Guarantee 03
Logs are optional and configurable
You choose whether to expose any logs to Scalekit for support. Default configuration: no log access.
Guarantee 04
No PHI or PII stored by Scalekit
Scalekit never stores PHI or PII, even in cloud mode. In on-prem, there is no Scalekit in the data path at all.
Pre-Sales Technical Questions

What buyers ask before they license

Does scalekit on-prem require internet access?

In air-gapped mode, no internet access is required after initial deployment. Connector logos and static assets are bundled in the image. Kubernetes image pulls happen from your internal registry. In VPC mode, there may be outbound calls for license validation and update channels — these are configurable and can be routed through your egress controls.

We’re using Docker, not Kubernetes. does on-prem still work?

Yes. Docker Compose packaging is available for development, testing, and lower-scale deployments. For production at enterprise scale, Kubernetes with Helm is recommended.

What exactly does Scalekit store in on-prem mode?

Nothing on our infrastructure. In on-prem mode, all data — user records, sessions, OAuth tokens, access keys — is stored in your Postgres instance, inside your deployment. Scalekit has no database access and no visibility into your stored data.

How does licensing work if we have 50 customers each needing their own deployment?

Licensing is per deployment. Each isolated customer instance gets its own license key. In air-gapped mode, validation is fully offline — no activation call required. Contact us to discuss volume pricing for multi-tenant deployment scenarios.

Who owns access when multiple agents are in the chain?

Each agent authenticates independently through the token vault. Credentials are scoped per agent, per user, per connector — there is no shared credential pool. The gateway enforces scope isolation at call time, so a downstream agent in a chain cannot escalate to credentials it wasn't explicitly granted.

Is Scalekit a sub-processor in an on-prem deployment?

No. In an on-prem deployment, no data reaches Scalekit infrastructure. We are not in the data processing chain. Scalekit is not listed as a sub-processor for on-prem customers. Under HIPAA, we can sign a BAA as a business associate; under GDPR, there is no data processing role to document.

Looking for an on-prem
deployment?

Your deployment model, as many instances as you need, and your compliance requirements. HIPAA, FedRAMP, CMMC, or your own internal security policy.