โ˜๏ธ

Deployment

Deployment Models

EchelonGraph is offered in two deployment models: the hosted service (SaaS) and a self-hosted deployment in your own infrastructure.

SaaSSelf-Hosted
Data locationEchelonGraph's Google Cloud project โ€” where each store isYour own infrastructure
Data egressTo our managed environmentNone โ€” zero egress
Who managesEchelonGraphYour team (with our support)
Encryption keysEchelonGraph-managedCustomer-managed (BYOK)
Best forStartups, small teamsEnterprise, government, finance, healthcare

A dedicated hosted instance (an isolated environment run by EchelonGraph for one organization) is not offered. The hosted service has no choice of region: EU and APAC data residency is planned but not yet available on any plan.


SaaS (Managed)

Book a demo and we provision your workspace โ€” no infrastructure to manage. Your data is stored with complete tenant isolation, and we handle all operations, scaling, and updates.


Self-Hosted (Enterprise)

For organizations with strict data sovereignty requirements, EchelonGraph can be deployed entirely inside your own infrastructure:

  • All scanning runs in your cloud, authenticating with your own service accounts
  • All data stays in your databases inside your network boundary
  • All dashboards are served behind your internal load balancer
  • Zero egress โ€” nothing leaves your network
  • BYOK encryption โ€” your encryption keys protect everything
  • Air-gapped support โ€” pull CVE feed and rule pack updates on your own schedule

Self-hosted deployments use the exact same product as the SaaS offering. See Data Sovereignty for details.


Kubernetes Support

EchelonGraph provides a Helm chart for Kubernetes-native deployments, packaging all services and dependencies for easy installation and management within your cluster. Contact our team for access.


Configuration

All services are configured via environment variables โ€” no secrets are embedded in container images. For production deployments, we recommend using a secrets manager (such as GCP Secret Manager, AWS Secrets Manager, or HashiCorp Vault) for all sensitive configuration values.

Detailed configuration guides are provided to Enterprise customers as part of onboarding.