Deployment

Three pathways.
None of them make
your data ours.

Where the control plane runs is an infrastructure decision, and organizations land in different places on it. What stays the same across all three is what we are permitted to do with what it holds. Which is nothing.

You run it

On-premises

The control plane and its database run on your own servers, inside your own network. This is the pathway most regulated organizations choose, and the only one that works with no outbound connection at all.

Where the data lives Entirely on your infrastructure. No component we operate sits in the path, so captured content never crosses a boundary you do not control.
  • You hold the database, backups and encryption keys
  • Air-gap capable — no outbound connection required
  • Your patching cadence and your uptime
  • ·You operate it, including upgrades
Your cloud, our software

Bring your own cloud

We deploy and operate Evidarch inside your AWS, Azure or GCP account. You own the account, the storage and the keys. We hold scoped access to run the software in it.

Where the data lives In your cloud account, in the region you choose. It never moves to infrastructure we own, and revoking our access leaves the data with you.
  • Your account, your region, your residency rules
  • We handle deployment, upgrades and monitoring
  • Access is scoped, logged and revocable by you
  • ·Your cloud spend, billed by your provider
We run it

SaaS

We operate the control plane for you on infrastructure we manage, in a single-tenant instance with its own database. This is the fastest way to start. It is also the only pathway where captured content reaches servers we run.

Where the data lives On infrastructure we operate, in the region you choose, isolated per customer. We are a processor acting on your instructions: the data remains yours throughout, and you can export or delete it at any time.
  • Running the same afternoon, nothing to operate
  • Single-tenant database, encrypted at rest and in transit
  • Export everything, or have it deleted, on request
  • ·Content is processed on infrastructure we operate

On-device redaction runs identically in all three. Secrets and personal data are stripped before the event leaves the machine that captured it. So what differs between these pathways is where the already-redacted record is stored, not whether raw secrets travel.

Our commitment

We do not use your data. For anything.

This is a contractual term rather than a preference, and it holds on every pathway including the one we host. Specifically:

  • noWe do not train models on it. Not our models, not anyone's. Your prompts are not a dataset, and no part of our business depends on them being one.
  • noWe do not read it. Support staff have no standing access to captured content. Where an incident genuinely requires it, access is time-boxed, requires your written approval, and is logged where you can see it.
  • noWe do not sell or share it. Not to advertisers, not to data brokers, not to partners, not in aggregate, not anonymised, not ever.
  • noWe do not analyse it for our own purposes. No benchmarking, no product analytics on your content, no “insights” derived from your corpus.
  • noWe do not retain it after you leave. Deletion on termination is a term of the contract with a stated deadline, not a courtesy.

We make money from software licences and support. Not from attention, advertising or data. That is why these commitments cost us nothing to make, and would cost us everything to break.

Side by side

The differences that actually matter.

Everything else is identical across the three: features, collectors, the ledger, verification.

 On-premisesYour cloudSaaS
Captured content stored onYour serversYour cloud accountOur infrastructure
Who holds the encryption keysYouYouUs, per customer
Who operates upgradesYouUsUs
Data residency controlAbsoluteYour region choiceYour region choice
Works air-gappedYesNoNo
On-device redactionYesYesYes
We can read your contentNever possibleNever possibleOnly with written approval, logged
Used for training or analyticsNoNoNo
Time to runningAn afternoonAbout a weekSame day
Choosing

Which one you probably want.

Pick on-premises if…

You are in a regulated sector, you have a platform team, or your answer to “can a third party hold this” is simply no. Nothing leaves the building.

Pick your own cloud if…

You want the residency and ownership of running it yourself, without operating it. This is common where procurement demands the data stay in a named account and region but the team has no capacity to run another service.

Pick SaaS if…

You need evidence this quarter and have no infrastructure to spare. Many organizations start here to prove the value, then move to their own cloud — the ledger exports and moves with them.

Moving later

The ledger is a PostgreSQL database and a documented event format. Migrating between pathways is an export and an import, and the hash chain verifies identically on the other side. That is rather the point of it.

Next

Not sure which fits?

Tell us your constraints: sector, residency requirements, whether you have a platform team. We will tell you which pathway we would actually recommend.