SaaS โ Self-Hosted
Export tenant data via the Enterprise admin console, install the Helm chart, import the bundle. Connectors need to be re-bound to your cluster's workload identity.
Same product, same commercial tiers, different operating model. Here's the honest breakdown.
| Dimension | SaaS | Self-Hosted |
|---|---|---|
| Data residency | US or EU | Any region you choose |
| Data leaves your boundary | Cloud metadata only, to our SaaS region | Never |
| Infrastructure you run | None | Kubernetes + Postgres + Redis + object storage |
| Install time | Minutes | Half a day (first cluster) |
| Upgrade cadence | Continuous (ours) | Monthly recommended (yours) |
| Cloud access model | Cross-account role, Entra federation, WIF. trusted to our SaaS identity | Same, trusted to your in-cluster workload identity |
| MFA | Mandatory (TOTP or WebAuthn) | Configurable; mandatory by default |
| SSO | Enterprise | Enterprise |
| Tenancy | Multi-tenant with RLS + per-tenant KMS | Single-tenant (you own the cluster) |
| Reports | Delivered by email + signed URL | Delivered to your S3-compatible bucket |
| Audit retention | 30 days / 1 year / 7 years | Your choice, bounded by your storage |
| Support | Community / Business hours / 24/7 | Community / Business hours / 24/7 + RCA support |
| Best for | Time-to-value, managed operations, US/EU residency | Sovereignty, GovCloud, classified, FedRAMP-style regimes |
Export tenant data via the Enterprise admin console, install the Helm chart, import the bundle. Connectors need to be re-bound to your cluster's workload identity.
Export the bundle, open a SaaS tenant, import. We'll help you re-issue the cross-account roles. Plan about a week end-to-end.