# Deployment Options Capsule Security offers flexible deployment models to meet your organization's security, compliance, and data residency requirements. All deployment options maintain our **SOC 2 Type 2** and **ISO 27001** certifications, ensuring enterprise-grade security regardless of your chosen architecture. ## Deployment Models ### Enterprise SaaS (Multi-Tenant) Our multi-tenant SaaS deployment provides the fastest path to securing your AI agents with zero infrastructure management. **Key Features:** - Multi-tenant architecture with strong logical tenant isolation - Fully managed by Capsule Security - Data encrypted at rest and in transit - Automatic updates and maintenance - Standard internet connectivity **Best For:** Organizations that want rapid deployment and minimal operational overhead. ### Customer Dedicated SaaS with BYOK Dedicated infrastructure with Bring Your Own Key (BYOK) encryption provides enhanced security and data sovereignty while Capsule Security manages the platform. **Key Features:** - Dedicated infrastructure for your organization - Bring Your Own Encryption Key (BYOK) support - Enhanced data sovereignty and control - Customer controls encryption keys - Standard internet or VPN connectivity options **Best For:** Organizations with strict data control requirements or specific encryption key management policies. ### Customer Hosted VPC ![Customer Hosted VPC Architecture](/assets/deployment-customer-vpc.cb64e87e3cb82d87dbe9983be8f815e94da1ce616bca69f94fd301cce1356572.9c1bb791.png) Maximum data isolation with the database residing in your own VPC while Capsule Security manages the control plane. **Key Features:** - Database resides in customer's VPC - Control plane managed by Capsule Security - Maximum data isolation and control - VPC peering or Private Link connectivity - Customer maintains full control over data storage **Best For:** Organizations requiring complete data isolation or those with strict regulatory requirements. [View detailed AWS deployment guide →](/guides/deployment-customer-vpc) ## Deployment Comparison | Deployment Model | Data Location | Control Plane | Network Setup | Primary Advantage | | --- | --- | --- | --- | --- | | Enterprise SaaS | Capsule Security cloud (multi-tenant) | Capsule Security managed | Standard internet | Fastest deployment, zero infrastructure management | | Dedicated SaaS with BYOK | Capsule Security cloud (dedicated) | Capsule Security managed | Standard internet or VPN | Enhanced security with customer-controlled encryption | | Customer Hosted VPC | Customer VPC | Capsule Security managed | VPC peering or Private Link | Full data isolation and control | ## Compliance & Security All deployment models are designed to meet stringent compliance requirements: - **SOC 2 Type 2 Certified** - Annual audits verify our security controls - **ISO 27001 Certified** - Information security management system compliance - **Data Encryption** - All data encrypted at rest and in transit - **Access Controls** - Role-based access control with audit logging - **Regular Security Assessments** - Continuous vulnerability scanning and penetration testing ## Choosing the Right Deployment Model ### Consider Enterprise SaaS if you: - Want the fastest time to value - Prefer a fully managed solution - Have standard compliance requirements - Want automatic updates and maintenance ### Consider Dedicated SaaS with BYOK if you: - Require dedicated infrastructure - Need to manage your own encryption keys - Have enhanced data sovereignty requirements - Want Capsule Security to manage operations ### Consider Customer Hosted VPC if you: - Must keep data within your own infrastructure - Have strict regulatory requirements for data residency - Need maximum control over data storage - Require network-level isolation [Learn more about Customer Hosted VPC deployment →](/guides/deployment-customer-vpc) ## Next Steps - [Get started with Agent Management](/guides/agent-management) - Contact our team at [support@capsule.security](mailto:support@capsule.security) to discuss your deployment requirements