DEPLOYMENT
Your data. Your perimeter.
Hosted SaaS, your own S3, in-VPC, or fully air-gapped - in every mode the audit trail stays verifiable and in your control.
Hosted
Live in minutesobsvr Cloud runs the ingest, PII scanning, signing, and Merkle ledger. Per-customer isolation, no infrastructure to manage.
- —Zero infra - wrap your SDK and events land immediately
- —Isolated, per-customer storage by default
- —Fastest path to a working audit trail
Bring-your-own storage
Your S3, your keysAudit records write directly to an S3 bucket in your own AWS account via a cross-account IAM role you control. No secret keys change hands.
- —Cross-account IAM role - obsvr assumes it with short-lived creds
- —Records land as date-partitioned JSON, Athena-ready
- —Dashboard generates the bucket policies for copy-paste
In-VPC data plane
Prompts never leaveThe full pipeline (ingest, PII scanning, signing, Merkle ledger) ships as a Helm chart and runs as containers inside your own VPC. Only content hashes, signatures, and verdicts sync out.
- —Raw prompts and responses never leave your network
- —You hold the countersigning key and the Merkle anchor repo
- —Deploys to your AWS account with your existing tooling
Air-gapped on-prem
No outboundFully self-hosted with no outbound connections - for financial institutions and government-adjacent environments where nothing leaves the perimeter.
- —REST API works from any environment that can make an HTTP call
- —Audit trail verifies without trusting external infrastructure
- —Built for the strictest data-residency and procurement reviews
In-VPC mode: what leaves your network
The enforcement and audit pipeline runs entirely in your VPC. Only the proof syncs to the control plane - never the content it proves.
You hold the countersigning key and the Merkle anchor repo - the audit trail verifies without trusting obsvr's infrastructure.