Deployments for every team's needs
Unlock all of Falconer from the hosting option that fits your compliance line or security goals: multi-tenant cloud to single-tenant in your own cloud account.
Three ways to deploy Falconer
Multi-tenant SaaS
Fully managed by Falconer on AWS. Encrypted at rest and in transit, isolated per organization.
Best forTeams that want zero infra overhead
Managed single tenant
Isolated single-tenant deployment in a dedicated Virtual Private Cloud (VPC), with complete network isolation, dedicated resources, and a branded subdomain. Falconer handles ops.
Best forTeams needing data isolation without running the stack
Self-hosted (cloud-prem)
Deploy as a single-tenant instance in your own cloud account, with infrastructure as code that's fully reviewable and auditable. You retain complete control, with private networking, no public ingress, and no egress beyond the model provider you approve.
Best forEnterprises that need full control over data privacy and compliance
Security posture
| Control | Multi-tenant | Single-tenant | Self-hosted |
|---|---|---|---|
| SOC 2 Type II | Included | Included | Included |
| HIPAA Compliance | Included | Included | Included |
| Encryption in transit and at rest | Included | Included | Included |
| Social login, SSO, SAML authentication | Included | Included | Included |
| Penetration testing | Included | Included | Included |
| Single-tenant deployment. Complete data isolation. | Not included | Included | Included |
| Private networking. No public egress beyond your approved model provider. | Not included | Not included | Included |
Full details on the security page and trust center.
Built for regulated teams
We work with teams that can't compromise on security or compliance. Bring us your requirements; we'll match the deployment.
Fintech and financial infrastructure
The context agents read, risk models, fraud logic, ledger internals, can't leak to a vendor or land in a training set.
Single-tenant isolation plus bring-your-own-key. Your models see your context; no one else does.
Health tech and healthcare informatics
PHI in your docs stays inside the compliance boundary, and the BAA has to cover what agents retrieve, not just the UI.
BAA extends to the MCP retrieval interface, not just the UI, on any hosting option. Every retrieval call is logged and permission-scoped.
Defense tech and public sector
The knowledge agents read has to stay in the enclave, reachable by coding agents, and current with the code.
Same MCP server and passage retrieval run inside your own cloud account with private networking, updated on every merged PR.
Multinational teams under residency law
Your context can't cross borders under GDPR, the EU AI Act, and localization rules in the US, India, Brazil, and Saudi Arabia.
Managed single tenant and self-hosted keep the platform and the context it processes inside the jurisdiction you're bound to.
Growth-stage AI companies
Everyone has the same models. Your architecture decisions and incident history are the context that sets you apart.
Isolated deployment keeps that context yours, and it stays current instead of going stale.
Frequently
Asked Questions
Can I move between deployment models later?
Yes. It's the same product in every mode, so migrations are configuration changes, not re-platforming. Most teams start on multi-tenant SaaS to prove value fast, then move to managed single tenant or self-hosted as compliance requirements tighten. Your documents, permissions, and integrations carry over. Talk to us about a migration path.
Do self-hosted deployments lose any features?
No. Freshness detection, passage-level retrieval, permission-aware access, and the read/write MCP server all run the same way in your own cloud account. All container images are pre-baked into the deployment image at build time, so nothing is pulled from a public registry for licensing, telemetry, or updates after install. Model inference is the one outbound dependency: Falconer calls the provider you approve, under your own key if you use bring-your-own-key. The full security posture is published at our Trust Center.
Can we use our own AI model keys?
Yes. For Enterprise customers, bring-your-own-key lets you supply your own OpenAI, Anthropic, or other provider keys, so model inference stays under your control and billing. You choose which providers are approved and can revoke access. See the security page for details.
Which AI models does Falconer run on?
Falconer is model-agnostic. On multi-tenant SaaS and managed single tenant we run frontier models out of the box; on self-hosted you point Falconer at the providers you've approved via bring-your-own-key, or at any OpenAI-compatible endpoint you run inside your own perimeter, including an open-weight model on your own GPUs. Talk to us about your model requirements.
How is each deployment priced?
Multi-tenant SaaS is self-serve; managed single tenant and self-hosted are enterprise deployments scoped to your environment. See pricing for plan details, or talk to us to scope an isolated deployment.
Is a BAA available for HIPAA-covered environments?
Yes, on any of the three hosting options, and coverage extends to the agent retrieval interface, not just the UI. Every retrieval call is logged and permission-scoped, so your security team can audit exactly what agents accessed. Full compliance detail lives in our Trust Center.
How does Falconer keep our data private?
Your content is never used to train external models, and there's no lock-in: you retain ownership at all times, with data export and clear deletion procedures on request. Each organization's data is isolated, encrypted in transit and at rest, and access is time-limited and fully logged. See the security page for the complete model.