Managed operations for SAFi
We operate SAFi. You own everything.
SAFi is an open-source runtime governance engine for agentic AI. It enforces your policies in real time, governs every tool call, and records every decision for audit. RunSAFi deploys, secures, monitors and maintains a dedicated SAFi instance inside your own environment, while your organization keeps the infrastructure, the data, the model keys and the governance records.
No new vendor cloud to vet. No data-residency fight. Bring your own model keys.
Your environment. Your data. Your keys. Your governance. Our operational expertise.
We bring our talent. You bring your resources.
SAFi is open source and designed to be self-hosted. You can operate it yourself, or we can act as your managed operator while your team builds the confidence and capability to take over. It is a practical way to begin without introducing a new vendor-hosted data boundary or committing to long-term operational dependence.
The situation
You have decided to govern your AI agents. Now someone has to run it.
Legal and compliance want policies enforced at runtime and an audit record that holds up in a review. Your platform team already has a backlog. Standing up a governance engine, and then keeping it patched, backed up, monitored and integrity-verified, is real, ongoing operational work.
Self-hosting is the right call
Your charter, policies and audit trail belong in your database, not a vendor's. That is exactly why SAFi is built to be self-hosted, and exactly what makes day-one operations your problem.
A hosted SaaS reopens the question
Handing governance data to a vendor cloud means a new boundary to vet, a new data-residency conversation, and a new dependency in the one system meant to prove your independence.
So we operate it where you already are
SAFi runs on your Linux machine, in your account, behind your egress rules. We hold admin on that one machine and do the operational work. Nothing else moves.
Why organizations choose this model
Expert operations without a new vendor boundary
Keep SAFi inside your boundary
Your deployment runs in your environment, whether in-house servers or your own Azure, AWS or GCP account, rather than in a separate vendor-controlled cloud.
Start with expert support
We handle deployment, updates, monitoring, backups, tested restores and routine health work from the first day, on a published release.
Keep the critical assets
Your infrastructure, model provider keys, data, policies and governance records stay yours throughout. We never see the keys.
Reduce lock-in
The software is open source. You can inspect it, verify the running release, restrict our access, and revoke it whenever you decide.
Verifiable integrity
We attest that the running Core Loop matches an official SAFi release by its published TCB Fingerprint, and your team can verify that independently.
A path to self-operation
We can train your IT team to assume the operator role whenever you want it. The exit is designed in, not negotiated later.
How it works
We operate, you own
One clean line between the operator role and ownership. Everything that carries risk, cost or control stays on your side of it.
What we bring
The operator role
- Deployment from a published, integrity-verified SAFi release onto your Linux machine.
- Secure access at your own domain over HTTPS, plus first-run configuration.
- Updates on the release cadence, and security hotfixes promptly.
- Monitoring, backups and tested restores.
- Integrity attestation against the release TCB Fingerprint, reported on a recurring schedule.
- Incident response and routine health work: resource tuning, log rotation.
- Training for your IT team to take over the operator role.
What you bring
Ownership and resources
- Your environment: in-house servers, your own cloud account, or a provider we recommend and size.
- Your AI model provider keys, which you enter and rotate yourself. Our procedures are designed so we cannot access their contents.
- Your policies, agents and users, set up self-serve or with our help.
- Ownership of all governance records and conversation data, at rest on your machine.
- Approval of change windows for deployments and upgrades.
- Control of our access, which you issue, audit, restrict and can revoke.
How we charge
Hourly to get live, then a flat monthly fee
You pay your hosting provider for the machine at cost, with no markup from us. Your model usage is billed by your AI provider directly, because the keys are yours.
Setup: time and materials
Installing SAFi is quick; getting your organization live involves your security review, access provisioning and policy design. Billed hourly against an estimate with a not-to-exceed cap agreed up front.
Run: flat monthly
A predictable fee covering updates, monitoring, backups, incident response and integrity attestation, with SLA tiers for teams and enterprises.
Bring your own keys
You pay your model provider directly for tokens. We never front, mark up or pool your model spend.
The software we operate
SAFi is open source, and stays that way
SAFi compiles your charter and policies into a value set, drafts each response and evaluates it value by value, then approves, blocks or redirects it before delivery. Tool calls run only through an agent's allow-list. Every governed turn produces an auditable record (the draft, the value-by-value ledger, the enforcement decision, the action taken and the exact policy version in force), journaled to a hash-chained audit trail.
Nothing about the managed service is proprietary. You can read the code, run the demo, deploy it yourself with Docker, and verify the release we install for you.
Five principles that hold whoever operates it
These are properties of the software's design, not of the operator. Handing us the admin credentials changes none of them.
- Value Sovereignty You decide the mission and values your AI enforces, not the model provider.
- Full Traceability Every governed turn is logged, explainable and auditable.
- Model Independence Your charter, policies and audit trail live in your database.
- Long-Term Consistency Measure drift against your ethical identity rather than guessing.
- Governed Action Every tool call is checked against the allow-list before it runs.
Start with a managed SAFi deployment
If you want to pilot or use SAFi but do not want your team to carry the full operational burden immediately, we can help. Tell us about your environment and we will come back with a scoped estimate.
