Four deployment models, one platform. From fully air-gapped to fully managed — the register, assessments, and incident records never leave the boundary you choose.
Deployed by your team on your infrastructure, behind your controls, inspectable by your auditors. Vendor-master sync via API or flat-file.
For estates where no external connection is acceptable. Flat-file ingestion, offline regulatory-dataset updates, zero-AI or BYO-inference inside the gap.
A dedicated instance in EU jurisdiction, transparent about its operating entity. No shared tenancy, no co-mingled data.
Same platform, single-tenant, managed by us. And when you're ready to bring it inside your walls, the deployment moves with you — nothing to re-buy, nothing to migrate away from.
A Frankfurt data center run by a US entity is still within reach of the US CLOUD Act — residency is not jurisdiction. Every major ratings platform is US-headquartered SaaS. Self-hosted or air-gapped Polestead removes the question entirely; the EU cloud and managed SaaS tiers are EU-resident, single-tenant, and transparent about who operates them.
It exists to be reachable — by prospects, customers, and auditors. Public-by-design content lives where the public can reach it; everything else stays behind your boundary.
On-premises, air-gapped, single-tenant EU cloud, and managed single-tenant SaaS.
Self-hosted and air-gapped deployments keep data in your environment, removing the cross-border compulsion question entirely.
No. The Trust Center is always SaaS by design — it exists to be reachable by prospects, customers, and auditors.