Enterprise
Self-hosted is not a different backend. It is the managed product pointed at a database you own, shipped as signed container images you run with Docker Compose, with the team layer running entirely on your side.
$ docker compose up -d
pathrule-app signed image · running
pathrule-web signed image · running
pathrule-mcp signed image · running
your database, your identity provider, your backups
db postgres://internal.acme.corp
sso okta (saml)
control plane holds licensing only, never your data
Answered before it asks them.
AI is a toggle
Two modes, your choice. Use our hosted proxy and we meter usage, or point the deployment at your own provider key so AI traffic goes straight to you.
No hard lockout
The deployment is gated by an entitlement licence, not a live billing dependency. On expiry, writes pause while reads and existing data stay available.
Built for review
Audit logs, role-based access control and signed images with an SBOM. Data residency comes for free, because the data never leaves your infrastructure.
The full team layer, on your infra
The deployment runs the complete stack. Realtime sync, live activity and overlapping-write detection all work with no traffic leaving your environment.
Your identity provider
Users sign in through your own SSO over SAML or OIDC. Microsoft Entra ID, Okta and Google Workspace are the first certified.
Signed images, sequential upgrades
Delivered as signed containers you run with Docker Compose. Latest and previous major versions are supported, customer-triggered, with a restore runbook.
Two planes, and the line between them is the point of the deployment.
01
Your side, the data plane
Your database, your data, your backups, your identity. Everything your team authors stays on your infrastructure.
02
Our side, the control plane
Licensing and entitlement, the commercial relationship, and the closed source. We never hold your data.
Users authenticate through your own provider over SAML or OIDC. Microsoft Entra ID, Okta and Google Workspace are the first certified.