Self-hosted & on-premises

Run Beacon in
your own environment

The same Beacon compliance engine, deployed inside your boundary — your datacenter, or your own AWS, GCP, or Azure account. Your clients' compliance data never leaves infrastructure you control, while Beacon keeps the install current with managed updates, signed licensing, and support.

Built for teams that have to keep the data home

Self-hosted Beacon is for regulated MSPs, public-sector and EU customers, and anyone whose data-residency rules say compliance data cannot leave their boundary.

Data sovereignty & residency

Every scan result, finding, and report stays inside infrastructure you own and operate. Compliance data never leaves your boundary and Beacon never sees it — which makes residency and sovereignty requirements straightforward to satisfy.

Air-gapped supported

Beacon runs with no outbound internet to Beacon at all. Entitlements are enforced offline through a signed license file, and updates can be applied from a transferred image bundle — the install never has to phone home.

Same product, your control

It is the same Beacon — the same compliance engine, the same checks across Azure, AWS, and GCP, the same portal. You run the stack; Beacon ships versioned, signed container images, managed updates, and support behind it.

Signed licensing & managed updates

A signed, offline license file gates entitlements with no SaaS dependency. New versions arrive as signed image tags or air-gapped bundles, and your admins can check for and apply updates from inside the portal under System → Updates — with a backup, health-check, and automatic rollback on failure.

SaaS vs self-hosted

Same product, two deployment models. The difference is who runs the stack and where the data lives — drawn directly from our published responsibility split.

Who hosts the stack

Beacon SaaS

Beacon runs and operates the entire platform — API, workers, portal, database, and Redis — in our cloud. You sign in and connect tenants.

Self-hosted

You run the entire runtime stack — API, worker, portal, PostgreSQL, Redis, reverse proxy — on your Docker host(s) or your own cloud account. Beacon provides only the images.

Where the data lives

Beacon SaaS

Compliance data is stored in Beacon's managed, encrypted database in our EU infrastructure, under our security controls.

Self-hosted

All compliance and customer data stays inside your boundary. Beacon never sees it. You own and back up the PostgreSQL database.

Updates

Beacon SaaS

Beacon ships updates continuously. There is nothing for you to install or schedule.

Self-hosted

Beacon publishes versioned, signed releases; you decide when to apply them — from the portal's System → Updates flow or the CLI. Air-gapped installs update from a transferred bundle.

Outbound network

Beacon SaaS

Handled entirely by Beacon. Beacon reaches out to the cloud-provider APIs it scans on your behalf.

Self-hosted

The only outbound traffic that must leave your network is your worker reaching the cloud-provider APIs being scanned (Azure / Microsoft Graph, AWS, GCP). Everything else is self-contained; an optional HTTPS proxy is supported.

Billing

Beacon SaaS

Self-serve subscription plans, billed monthly or annually by card.

Self-hosted

Contract and license based — no in-product billing. Entitlements come from a signed license file Beacon mints for you. Talk to sales for a quote.

In both models you supply read-only scan credentials for the cloud accounts being assessed and Beacon scans them without write access. On self-hosted, you additionally own the host OS, TLS certificates, secrets, backups, and disaster recovery; Beacon owns the images, the license, and the update channel.

How a self-hosted install works

A packaging and licensing model designed so you never receive Beacon's source, and your install stays upgradeable.

01 — Deploy

One compose file, one .env

Stand up the full stack on your own Docker host(s) from pre-built, signed images — by registry pull or an air-gapped tarball bundle. Per-cloud guides cover AWS, GCP, and Azure, for a single VM or managed Postgres and Redis.

02 — License

Offline signed license

Beacon mints a signed license file that the runtime verifies offline — no phone-home. It carries your entitlements and caps and keeps working even if Beacon is unreachable.

03 — Update

In-portal updates

Your admins see when a new version is available and apply it from System → Updates: backup, pull or load, migrate, recreate, health-check, and automatic rollback on failure. The CLI path is always available too.

Want Beacon inside your own walls?

Self-hosted Beacon is contract and license based. Tell us about your environment — datacenter, cloud account, or air-gapped — and we will scope the right deployment with you.

Contact sales

Or email us directly at hello@beaconmsp.io.