Three pathways.
None of them make
your data ours.
Where the control plane runs is an infrastructure decision, and organizations land in different places on it. What stays the same across all three is what we are permitted to do with what it holds. Which is nothing.
On-premises
The control plane and its database run on your own servers, inside your own network. This is the pathway most regulated organizations choose, and the only one that works with no outbound connection at all.
- ✦You hold the database, backups and encryption keys
- ✦Air-gap capable — no outbound connection required
- ✦Your patching cadence and your uptime
- ·You operate it, including upgrades
Bring your own cloud
We deploy and operate Evidarch inside your AWS, Azure or GCP account. You own the account, the storage and the keys. We hold scoped access to run the software in it.
- ✦Your account, your region, your residency rules
- ✦We handle deployment, upgrades and monitoring
- ✦Access is scoped, logged and revocable by you
- ·Your cloud spend, billed by your provider
SaaS
We operate the control plane for you on infrastructure we manage, in a single-tenant instance with its own database. This is the fastest way to start. It is also the only pathway where captured content reaches servers we run.
- ✦Running the same afternoon, nothing to operate
- ✦Single-tenant database, encrypted at rest and in transit
- ✦Export everything, or have it deleted, on request
- ·Content is processed on infrastructure we operate
On-device redaction runs identically in all three. Secrets and personal data are stripped before the event leaves the machine that captured it. So what differs between these pathways is where the already-redacted record is stored, not whether raw secrets travel.
We do not use your data. For anything.
This is a contractual term rather than a preference, and it holds on every pathway including the one we host. Specifically:
- noWe do not train models on it. Not our models, not anyone's. Your prompts are not a dataset, and no part of our business depends on them being one.
- noWe do not read it. Support staff have no standing access to captured content. Where an incident genuinely requires it, access is time-boxed, requires your written approval, and is logged where you can see it.
- noWe do not sell or share it. Not to advertisers, not to data brokers, not to partners, not in aggregate, not anonymised, not ever.
- noWe do not analyse it for our own purposes. No benchmarking, no product analytics on your content, no “insights” derived from your corpus.
- noWe do not retain it after you leave. Deletion on termination is a term of the contract with a stated deadline, not a courtesy.
We make money from software licences and support. Not from attention, advertising or data. That is why these commitments cost us nothing to make, and would cost us everything to break.
The differences that actually matter.
Everything else is identical across the three: features, collectors, the ledger, verification.
| On-premises | Your cloud | SaaS | |
|---|---|---|---|
| Captured content stored on | Your servers | Your cloud account | Our infrastructure |
| Who holds the encryption keys | You | You | Us, per customer |
| Who operates upgrades | You | Us | Us |
| Data residency control | Absolute | Your region choice | Your region choice |
| Works air-gapped | Yes | No | No |
| On-device redaction | Yes | Yes | Yes |
| We can read your content | Never possible | Never possible | Only with written approval, logged |
| Used for training or analytics | No | No | No |
| Time to running | An afternoon | About a week | Same day |
Which one you probably want.
Pick on-premises if…
You are in a regulated sector, you have a platform team, or your answer to “can a third party hold this” is simply no. Nothing leaves the building.
Pick your own cloud if…
You want the residency and ownership of running it yourself, without operating it. This is common where procurement demands the data stay in a named account and region but the team has no capacity to run another service.
Pick SaaS if…
You need evidence this quarter and have no infrastructure to spare. Many organizations start here to prove the value, then move to their own cloud — the ledger exports and moves with them.
Moving later
The ledger is a PostgreSQL database and a documented event format. Migrating between pathways is an export and an import, and the hash chain verifies identically on the other side. That is rather the point of it.
Not sure which fits?
Tell us your constraints: sector, residency requirements, whether you have a platform team. We will tell you which pathway we would actually recommend.