Deployed where you decide. Controlled by you.
The platform installs inside your environment on infrastructure you control. There is no vendor cloud, no external account, and no telemetry — the deployment model is a security control, not a convenience trade-off.
Six supported shapes
On-premises core
Hardened container package for a single-environment deployment, installed by your ops team on your servers.
Enterprise Kubernetes
Stateless replicas plus a durable worker, suitable for customer-operated clusters.
Private / hybrid cloud
Architecture compatible with Azure Local and hybrid environments for Microsoft-heavy estates.
Connected private
Runs in your network with governed, signed update paths — no other external dependency.
Air-gapped
No external connectivity required. Updates and licences transfer offline as signed, verifiable files.
Pilot deployment
Laptop-class or single-server install for a fixed-scope pilot, upgradeable to production profiles.
Who runs what
| Area | Customer | mAIb Tech |
|---|---|---|
| Infrastructure, network, physical security | Owns and operates | Documents requirements |
| Identity provider and user lifecycle | Owns (your Entra/OIDC tenant) | Integrates and enforces roles in-product |
| Knowledge approval decisions | Your administrators approve | Provides the governed workflow and enforcement |
| Product updates | Applies via signed packages | Builds, signs and documents releases |
| Backups and restore drills | Operates on your storage | Provides tooling and drill procedure |
| Support access | Grants explicitly, time-limited | Off by default; every session audited |