Send your architecture team this page. It answers what they are going to ask anyway, in the order they usually ask it, and it says plainly where our answer is we do not claim that.
Studio runs on hardware you own, inside a boundary you already defend. Your firewall rules are the enforcement. Nothing here depends on trusting a promise we made in a questionnaire.
You do not have to take the paragraph above on trust. This is the real on-premise configuration, and your team can read every line of it before anything runs.
# the real config. no hidden endpoints. deployment.mode=onprem # inference points at your box, not ours OPENAI_BASE_URL=http://localhost:11434/v1 # ollama # no billing calls, no licence server razorpay.enabled=false paddle.enabled=false # your directory, your mail, your storage LDAP_ENABLED=true MAIL_HOST=smtp.internal
We do not hold SOC 2, ISO 27001, or HIPAA attestation, and we will not tell you otherwise to get through a procurement gate. We are a small company in Hyderabad. When we have an audit, it will be on this page with the report date.
We also do not publish an uptime SLA for self-hosted deployments, because we do not run them. Availability is your infrastructure. What we do commit to in the licence is a named support engineer and an agreed response time.
If your process requires a certified vendor, we are the wrong supplier today and we would rather say so now than in month four of a procurement cycle. If your process cares about where the data physically sits and who can reach it, keep reading, because that is the part we are built for.
We will walk your architecture and security reviewers through the compose file, the licence mechanism, and the network boundary, and answer the questions this page did not. Bring the questionnaire if you have one.