Deployment
Deployment Models
EchelonGraph is offered in two deployment models: the hosted service (SaaS) and a self-hosted deployment in your own infrastructure.
| SaaS | Self-Hosted | |
|---|---|---|
| Data location | EchelonGraph's Google Cloud project โ where each store is | Your own infrastructure |
| Data egress | To our managed environment | None โ zero egress |
| Who manages | EchelonGraph | Your team (with our support) |
| Encryption keys | EchelonGraph-managed | Customer-managed (BYOK) |
| Best for | Startups, small teams | Enterprise, government, finance, healthcare |
A dedicated hosted instance (an isolated environment run by EchelonGraph for one organization) is not offered. The hosted service has no choice of region: EU and APAC data residency is planned but not yet available on any plan.
SaaS (Managed)
Book a demo and we provision your workspace โ no infrastructure to manage. Your data is stored with complete tenant isolation, and we handle all operations, scaling, and updates.
Self-Hosted (Enterprise)
For organizations with strict data sovereignty requirements, EchelonGraph can be deployed entirely inside your own infrastructure:
- All scanning runs in your cloud, authenticating with your own service accounts
- All data stays in your databases inside your network boundary
- All dashboards are served behind your internal load balancer
- Zero egress โ nothing leaves your network
- BYOK encryption โ your encryption keys protect everything
- Air-gapped support โ pull CVE feed and rule pack updates on your own schedule
Self-hosted deployments use the exact same product as the SaaS offering. See Data Sovereignty for details.
Kubernetes Support
EchelonGraph provides a Helm chart for Kubernetes-native deployments, packaging all services and dependencies for easy installation and management within your cluster. Contact our team for access.
Configuration
All services are configured via environment variables โ no secrets are embedded in container images. For production deployments, we recommend using a secrets manager (such as GCP Secret Manager, AWS Secrets Manager, or HashiCorp Vault) for all sensitive configuration values.
Detailed configuration guides are provided to Enterprise customers as part of onboarding.