Back to overview
Private deployment routesCustomer-owned AWS or fully self-hosted

Ship AskMasked into the infrastructure model your client needs.

Use the assisted AWS tier when the customer needs to own the account, database, and keys but wants us to install the stack. Use full self-hosting when their team will operate the whole deployment lifecycle.

Install instructions for private deployments

Install commands are locked. Complete onboarding and checkout for customer-owned AWS or self-hosted deployment before repository access, license keys, and deployment instructions are shown.

Key and model control plane

Bring your own keys

Reference your own OpenAI, Anthropic, Gemini, or compatible gateway secrets from your vault and rotate on your schedule.

Use AskMasked managed keys

Fallback option for fast rollout, with managed lifecycle and audited access controls.

Clean model switching

Update provider and model values without changing user prompts or redaction logic.

Demo language: Security controls run where the customer owns the compute. AI providers are downstream processors of redacted text only.

Install manifest

No-secrets runbook for customer-owned deployments

The manifest defines ownership, required customer inputs, environment contract, smoke checks, and billing telemetry without exposing provider keys, database passwords, or protected client terms.

GET /api/deployment/install-manifest
Install manifest access is locked. Complete onboarding and checkout for customer-owned AWS or self-hosted deployment before install runbooks and repository access are shown.