The same Beacon compliance engine, deployed inside your boundary — your datacenter, or your own AWS, GCP, or Azure account. Your clients' compliance data never leaves infrastructure you control, while Beacon keeps the install current with managed updates, signed licensing, and support.
Self-hosted Beacon is for regulated MSPs, public-sector and EU customers, and anyone whose data-residency rules say compliance data cannot leave their boundary.
Every scan result, finding, and report stays inside infrastructure you own and operate. Compliance data never leaves your boundary and Beacon never sees it — which makes residency and sovereignty requirements straightforward to satisfy.
Beacon runs with no outbound internet to Beacon at all. Entitlements are enforced offline through a signed license file, and updates can be applied from a transferred image bundle — the install never has to phone home.
It is the same Beacon — the same compliance engine, the same checks across Azure, AWS, and GCP, the same portal. You run the stack; Beacon ships versioned, signed container images, managed updates, and support behind it.
A signed, offline license file gates entitlements with no SaaS dependency. New versions arrive as signed image tags or air-gapped bundles, and your admins can check for and apply updates from inside the portal under System → Updates — with a backup, health-check, and automatic rollback on failure.
Same product, two deployment models. The difference is who runs the stack and where the data lives — drawn directly from our published responsibility split.
Beacon runs and operates the entire platform — API, workers, portal, database, and Redis — in our cloud. You sign in and connect tenants.
You run the entire runtime stack — API, worker, portal, PostgreSQL, Redis, reverse proxy — on your Docker host(s) or your own cloud account. Beacon provides only the images.
Compliance data is stored in Beacon's managed, encrypted database in our EU infrastructure, under our security controls.
All compliance and customer data stays inside your boundary. Beacon never sees it. You own and back up the PostgreSQL database.
Beacon ships updates continuously. There is nothing for you to install or schedule.
Beacon publishes versioned, signed releases; you decide when to apply them — from the portal's System → Updates flow or the CLI. Air-gapped installs update from a transferred bundle.
Handled entirely by Beacon. Beacon reaches out to the cloud-provider APIs it scans on your behalf.
The only outbound traffic that must leave your network is your worker reaching the cloud-provider APIs being scanned (Azure / Microsoft Graph, AWS, GCP). Everything else is self-contained; an optional HTTPS proxy is supported.
Self-serve subscription plans, billed monthly or annually by card.
Contract and license based — no in-product billing. Entitlements come from a signed license file Beacon mints for you. Talk to sales for a quote.
In both models you supply read-only scan credentials for the cloud accounts being assessed and Beacon scans them without write access. On self-hosted, you additionally own the host OS, TLS certificates, secrets, backups, and disaster recovery; Beacon owns the images, the license, and the update channel.
A packaging and licensing model designed so you never receive Beacon's source, and your install stays upgradeable.
Stand up the full stack on your own Docker host(s) from pre-built, signed images — by registry pull or an air-gapped tarball bundle. Per-cloud guides cover AWS, GCP, and Azure, for a single VM or managed Postgres and Redis.
Beacon mints a signed license file that the runtime verifies offline — no phone-home. It carries your entitlements and caps and keeps working even if Beacon is unreachable.
Your admins see when a new version is available and apply it from System → Updates: backup, pull or load, migrate, recreate, health-check, and automatic rollback on failure. The CLI path is always available too.
Self-hosted Beacon is contract and license based. Tell us about your environment — datacenter, cloud account, or air-gapped — and we will scope the right deployment with you.
Contact salesOr email us directly at hello@beaconmsp.io.