Single-tenant deployment
The product is delivered as a Docker Compose stack the customer runs on their own infrastructure. There is no managed SaaS version.
Compliance On Demand is built for teams that cannot put scan credentials, compliance evidence or generated documents into a multi-tenant SaaS control plane. The customer runs the stack, pins releases and keeps evidence inside their own boundary.
What this page covers
Run compliance, posture scans, vendor risk, local AI and audit evidence inside a single-tenant deployment you control.
The product is delivered as a Docker Compose stack the customer runs on their own infrastructure. There is no managed SaaS version.
Policy drafting, report generation and questionnaire support can use the bundled Ollama and Gemma option instead of a third-party LLM.
Offline release bundles, air-gapped mode and offline licence attestations support controlled or disconnected environments.
Operational proof
These are the concrete operating claims this page should support in search results, sales calls and evaluator conversations.
Cloud credentials and generated documents stay on customer hosts
Images are cosign-signed and releases can be pinned to an exact version
SPDX SBOMs support supply-chain review
Diagnostics and backup tooling are designed for self-hosted operations
Questions
No. Compliance On Demand is designed as a self-hosted single-tenant product so sensitive assurance data remains in the customer's boundary.
Yes. The product supports air-gapped mode, offline release bundles and offline licence attestations for controlled deployments.
Product briefing
Share your deployment boundary, frameworks and evidence workflow, and we will talk through fit without generic compliance theatre.