Skip to content
Last updated

Deployment Options

Capsule Security offers flexible deployment models to meet your organization's security, compliance, and data residency requirements. All deployment options maintain our SOC 2 Type 2 and ISO 27001 certifications, ensuring enterprise-grade security regardless of your chosen architecture.

Deployment Models

Enterprise SaaS (Multi-Tenant)

Our multi-tenant SaaS deployment provides the fastest path to securing your AI agents with zero infrastructure management.

Key Features:

  • Multi-tenant architecture with strong logical tenant isolation
  • Fully managed by Capsule Security
  • Data encrypted at rest and in transit
  • Automatic updates and maintenance
  • Standard internet connectivity

Best For: Organizations that want rapid deployment and minimal operational overhead.

Customer Dedicated SaaS with BYOK

Dedicated infrastructure with Bring Your Own Key (BYOK) encryption provides enhanced security and data sovereignty while Capsule Security manages the platform.

Key Features:

  • Dedicated infrastructure for your organization
  • Bring Your Own Encryption Key (BYOK) support
  • Enhanced data sovereignty and control
  • Customer controls encryption keys
  • Standard internet or VPN connectivity options

Best For: Organizations with strict data control requirements or specific encryption key management policies.

Customer Hosted VPC

Customer Hosted VPC Architecture

Maximum data isolation with the database residing in your own VPC while Capsule Security manages the control plane.

Key Features:

  • Database resides in customer's VPC
  • Control plane managed by Capsule Security
  • Maximum data isolation and control
  • VPC peering or Private Link connectivity
  • Customer maintains full control over data storage

Best For: Organizations requiring complete data isolation or those with strict regulatory requirements.

View detailed AWS deployment guide →

Deployment Comparison

Deployment ModelData LocationControl PlaneNetwork SetupPrimary Advantage
Enterprise SaaSCapsule Security cloud (multi-tenant)Capsule Security managedStandard internetFastest deployment, zero infrastructure management
Dedicated SaaS with BYOKCapsule Security cloud (dedicated)Capsule Security managedStandard internet or VPNEnhanced security with customer-controlled encryption
Customer Hosted VPCCustomer VPCCapsule Security managedVPC peering or Private LinkFull data isolation and control

Compliance & Security

All deployment models are designed to meet stringent compliance requirements:

  • SOC 2 Type 2 Certified - Annual audits verify our security controls
  • ISO 27001 Certified - Information security management system compliance
  • Data Encryption - All data encrypted at rest and in transit
  • Access Controls - Role-based access control with audit logging
  • Regular Security Assessments - Continuous vulnerability scanning and penetration testing

Choosing the Right Deployment Model

Consider Enterprise SaaS if you:

  • Want the fastest time to value
  • Prefer a fully managed solution
  • Have standard compliance requirements
  • Want automatic updates and maintenance

Consider Dedicated SaaS with BYOK if you:

  • Require dedicated infrastructure
  • Need to manage your own encryption keys
  • Have enhanced data sovereignty requirements
  • Want Capsule Security to manage operations

Consider Customer Hosted VPC if you:

  • Must keep data within your own infrastructure
  • Have strict regulatory requirements for data residency
  • Need maximum control over data storage
  • Require network-level isolation

Learn more about Customer Hosted VPC deployment →

Next Steps