Run it on your hardware.
Single Go binary. Air-gap install. Ed25519-signed offline license. Your cloud, your data, no phone-home.
Deployment readiness
Single binary, Helm chart, or air-gap tarball.
Append-only events, configurable retention, export API.
SCIM 2.0 provisioning, OAuth provider sign-in, passkey policy.
TOTP, passkeys, step-up challenges, recovery codes.
Scoped bearer tokens, revocation, per-plan hard caps.
Telemetry opt-out, GDPR export, account deletion.
We walk through the deployment live, no slide decks. Cover what matters to your team: Helm chart or single-binary install, air-gap setup, SCIM provisioning, agent integration, or migrating existing repos.
- Compliance and auditAppend-only audit log, configurable retention up to seven years, GDPR export, and the audit-events API with RBAC gating.
- SCIM and SSOSCIM 2.0 user and group provisioning, OAuth provider sign-in (org-enforced SSO coming soon), and org-wide passkey policy enforcement.
- Self-host and air-gapSingle Go binary, offline Ed25519 license, no phone-home. Point inference at your own endpoint via OPENAI_BASE_URL.
- Agent integrationMCP server with scoped, revocable bearer tokens. Every agent action writes an audit row. Per-plan hard caps prevent runaway billing.
After you request a walkthrough
- One human reply within one business day confirming your request.
- A short pre-call questionnaire: deploy target, team size, compliance requirements.
- A shared folder with the architecture diagram, network data-flow map, and license agreement draft.
- A live session covering the specific axes your team cares about (no slide decks).
Questions before the call? Security and trust and Privacy policy are public.
No marketing list. One human reply within one business day.
Explore first
Browse before you deploy.
Walk the public fixture on our source, then request a self-host walkthrough when ready.