Managed Services
SAFi, deployed and operated in your own environment.
If you want to pilot or use SAFi but feel overwhelmed by the technology, we can help. We operate a dedicated SAFi instance in your environment while your organization retains ownership of the infrastructure, data, AI model keys and governance records. You bring the environment and resources. We bring the expertise to deploy, secure, monitor and maintain SAFi.
The managed path to SAFi
You do not have to become an expert in SAFi operations before you begin.
SAFi can run in your existing environment, including in-house servers or a trusted cloud account on Azure, AWS, GCP, or another provider that meets your requirements.
You provide the environment and your AI model provider keys. We deploy and operate SAFi on your behalf within that environment. Your data remains within your security boundary, your model costs are billed directly by your provider, and your team retains ownership of the complete deployment.
Because SAFi is open source, you are not surrendering control to a proprietary hosted service. You can inspect the software, verify the running release, restrict our access, revoke access when needed, and take over operations whenever you choose.
This model is designed for organizations that want to evaluate SAFi or put it into production without taking on the full operational burden on day one.
How it works
We operate, you own
What we bring
The operator role
- We provision and deploy SAFi on your Linux machine, from a published, integrity-verified release.
- We set up secure access at your own domain or subdomain (for example
safi.yourcompany.com) and the first-run configuration. - We apply updates on the release cadence, plus security hotfixes.
- We run monitoring, backups and tested restores.
- We attest integrity: the running Core Loop matches an official SAFi release by its published TCB Fingerprint, so your auditors can confirm the governance engine is unaltered. We provide recurring integrity reports, and your team can review the release and verify the running deployment themselves.
- We handle incidents and routine health work: resource tuning, log rotation.
- We can train your IT team to operate SAFi themselves, whenever you want it.
What you bring
Ownership and resources
- Your own environment: in-house servers, a cloud account (Azure, AWS, GCP, or elsewhere), or a hosting provider we recommend and size. SAFi runs inside your boundary; we operate it there.
- Your own AI model provider API keys. You enter and manage your own keys. SAFi stores them according to the deployment's configured security controls, and our operating procedures are designed to prevent us from accessing their contents.
- Your policies, agents and users, which you set up self-serve or with our help.
- Ownership of all governance records and conversation data, at rest on your machine.
Environment and deployment
What the machine has to be
Your OS is Linux
All of SAFi's tooling and the reference deployment assume Linux. This is a requirement, not a preference.
Docker or bare-metal, depending on the need
SAFi can be deployed using Docker, or as a bare-metal installation with system services, a Python virtual environment and a reverse proxy. We confirm the supported deployment path during scoping, based on the current release documentation and your operating standards.
Data ownership and egress
Where your data sits, and where requests go
Being honest about egress matters more than claiming a sealed box. Here is exactly what stays and what leaves.
SAFi stays in your environment
The software, your governance records and your conversation data remain at rest on your machine.
Requests may leave your tenant
SAFi sends prompts and data to the AI model providers and external tools that you configure. You control those providers, endpoints, credentials and egress rules.
You control the boundary
You place the SAFi machine in its own subnet or resource group with a tight egress allowlist: your model providers plus the tool and data endpoints you choose, nothing else.
We do not train on your data
We do not use your governance records or conversation data to train models. This is an operating commitment, not just a software default.
Access model
Admin on one machine, and nothing beyond it
We require administrative access to the SAFi host
So we can install system dependencies, deploy SAFi, manage configured tool servers and apply updates. This access is limited to the SAFi machine and does not extend to the rest of your environment unless you separately authorize integrations.
Root or equivalent privileges may be required
Depending on the deployment method. Running SAFi can require installing MCP tool servers, system packages and updates. This matches SAFi's own security model, where installing a tool is gated behind host access precisely because it can mean running external code.
We need no reach beyond that one machine
No other servers, no other databases, no broader access to your account.
You control our access
You grant controlled administrative access using credentials issued and governed by your organization. You retain the ability to audit, rotate, restrict and revoke that access at any time. Optional bastion access with session logging makes every administrative action we take reviewable by you.
You keep ultimate control
It is your machine in your environment. You can snapshot it, inspect it, restrict its egress, revoke our access, or power it off at any time.
Who does what
The responsibility split, line by line
| Area | We | You |
|---|---|---|
| Environment, networking, IAM | Advise | Own and pay |
| Access to the SAFi machine | Hold admin on that one machine | Grant, isolate, audit, and can revoke |
| Deploy and upgrades | Run them | Approve the windows |
| Backups and restore | Run them | Rely on them |
| Model provider keys | Never see them | Own and rotate them |
| Model usage cost | Not ours | Billed to you by your provider |
| Policies, agents, users | Help on request | Decide |
| Governance and conversation data | Never train on it | Own it |
| Integrity verification | Attest to it | Can verify it yourself |
| End-user support for your staff | Not ours | Your help desk |
Onboarding
Six steps to live
Usually a few days end to end, depending on how much policy setup you want from us.
-
Choose the environment and size
Your own servers or cloud, or our recommendation, sized to your expected load, starting small and scaling.
-
We provision and deploy
We stand up your Linux machine and deploy SAFi from a published, integrity-verified release, using the deployment path confirmed during scoping.
-
Domain, TLS and verification
Your domain goes live over HTTPS, and we confirm the running Core Loop matches the release by its TCB Fingerprint.
-
You add your API keys
Entered in the app, stored according to the deployment's security controls, never accessible to us through our operating procedures.
-
Set up your organization
Your policies, agents and users, self-serve or with our help.
-
Handover and go live
We hand over access, start monitoring, and the SLA clock begins.
A path to self-operation is built in
We can train your IT team to assume the operator role whenever you are ready. On exit you keep the machine, the keys and the data, with a clean handover, because the software was never ours to hold.
Scope
What this is not
Worth stating plainly, so the engagement starts with the same expectations on both sides.
- Not a reseller of model access. You bring your own keys and pay your provider directly.
- Not custom engineering. Operating stock SAFi is the service. Bespoke features or plugins are a separate engagement.
- Not your compliance team. SAFi produces the evidence; deciding your policies and reading your audit trail is your call, though we can advise.
- Not your help desk. We keep the platform running; supporting your own staff stays with your internal support.
Start with a managed SAFi deployment
Tell us about your environment, deployment requirements, security controls, expected usage and path to internal ownership. We will come back with a scoped estimate.
