# Deployment Options

Capsule Security offers flexible deployment models to meet your organization's security, compliance, and data residency requirements. All deployment options maintain our **SOC 2 Type 2** and **ISO 27001** certifications, ensuring enterprise-grade security regardless of your chosen architecture.

## Deployment Models

### Enterprise SaaS (Multi-Tenant)

Our multi-tenant SaaS deployment provides the fastest path to securing your AI agents with zero infrastructure management.

**Key Features:**

- Multi-tenant architecture with strong logical tenant isolation
- Fully managed by Capsule Security
- Data encrypted at rest and in transit
- Automatic updates and maintenance
- Standard internet connectivity


**Best For:** Organizations that want rapid deployment and minimal operational overhead.

### Customer Dedicated SaaS with BYOK

Dedicated infrastructure with Bring Your Own Key (BYOK) encryption provides enhanced security and data sovereignty while Capsule Security manages the platform.

**Key Features:**

- Dedicated infrastructure for your organization
- Bring Your Own Encryption Key (BYOK) support
- Enhanced data sovereignty and control
- Customer controls encryption keys
- Standard internet or VPN connectivity options


**Best For:** Organizations with strict data control requirements or specific encryption key management policies.

### Customer Hosted VPC

![Customer Hosted VPC Architecture](/assets/deployment-customer-vpc.cb64e87e3cb82d87dbe9983be8f815e94da1ce616bca69f94fd301cce1356572.9c1bb791.png)

Maximum data isolation with the database residing in your own VPC while Capsule Security manages the control plane.

**Key Features:**

- Database resides in customer's VPC
- Control plane managed by Capsule Security
- Maximum data isolation and control
- VPC peering or Private Link connectivity
- Customer maintains full control over data storage


**Best For:** Organizations requiring complete data isolation or those with strict regulatory requirements.

[View detailed AWS deployment guide →](/guides/deployment-customer-vpc)

## Deployment Comparison

| Deployment Model | Data Location | Control Plane | Network Setup | Primary Advantage |
|  --- | --- | --- | --- | --- |
| Enterprise SaaS | Capsule Security cloud (multi-tenant) | Capsule Security managed | Standard internet | Fastest deployment, zero infrastructure management |
| Dedicated SaaS with BYOK | Capsule Security cloud (dedicated) | Capsule Security managed | Standard internet or VPN | Enhanced security with customer-controlled encryption |
| Customer Hosted VPC | Customer VPC | Capsule Security managed | VPC peering or Private Link | Full data isolation and control |


## Compliance & Security

All deployment models are designed to meet stringent compliance requirements:

- **SOC 2 Type 2 Certified** - Annual audits verify our security controls
- **ISO 27001 Certified** - Information security management system compliance
- **Data Encryption** - All data encrypted at rest and in transit
- **Access Controls** - Role-based access control with audit logging
- **Regular Security Assessments** - Continuous vulnerability scanning and penetration testing


## Choosing the Right Deployment Model

### Consider Enterprise SaaS if you:

- Want the fastest time to value
- Prefer a fully managed solution
- Have standard compliance requirements
- Want automatic updates and maintenance


### Consider Dedicated SaaS with BYOK if you:

- Require dedicated infrastructure
- Need to manage your own encryption keys
- Have enhanced data sovereignty requirements
- Want Capsule Security to manage operations


### Consider Customer Hosted VPC if you:

- Must keep data within your own infrastructure
- Have strict regulatory requirements for data residency
- Need maximum control over data storage
- Require network-level isolation


[Learn more about Customer Hosted VPC deployment →](/guides/deployment-customer-vpc)

## Next Steps

- [Get started with Agent Management](/guides/agent-management)
- Contact our team at [support@capsule.security](mailto:support@capsule.security) to discuss your deployment requirements