Deployment

Your infrastructure, not ours.

Data privacy tooling that routes your data through someone else's cloud defeats its own purpose. Every VestraData deployment model keeps production data inside your boundary.

Model 01 · Cloud ApplianceDeploy into your own cloud account

Deploy into your own AWS, Azure, or GCP account. Your networking, your IAM, your storage. No production data routed to vendor infrastructure.

AWS MarketplaceAzure MarketplaceGCP MarketplaceTerraformCloudFormation
Model 02 · On-Premises / Air-GapRun inside a private data centre or restricted network segment

No internet dependency at runtime. For teams where operational data egress is ruled out by policy.

Docker ComposeHelm / KubernetesLDAPSAMLOffline licenseNo phone-home
Model 03 · SDKEmbed the detection and policy layer directly into your own workflow

Use the generated REST client or the embedded ML stack in-process when a standalone deployment is not the right fit.

PythonNode.jsJava.NETOpenAPI
What security teams ask

The questions that come up in vendor review.

Does any production data reach VestraData's infrastructure?
No. Every deployment model runs inside your boundary — your cloud account, your data centre, or your own process via the SDK. There is no vendor cloud in the data path.
Can it run with no internet access at all?
Yes. The on-premises model bundles the full ML stack in the install package, supports offline licensing, and makes no outbound calls at runtime.
How does it fit our identity and access setup?
LDAP and SAML are supported for enterprise identity. Credentials for data sources are encrypted per tenant and can be scoped read-only.
What does an evaluation deployment look like?
Typically Docker Compose in a sandboxed segment or your own cloud account, stood up in under a day.

Not sure which model fits?

Deployment is the first thing we settle in a technical review — before any scan runs.