Self-hosted & dedicated

Run Ollagraph
on your own infra.

Same API, same MCP server, same 148 endpoints — running in your VPC. Customer data never leaves your perimeter. Egress goes through your proxies. You hold the keys. We don't see anything.

Talk to us → Architecture docs
WHY SELF-HOST

Six reasons teams pick the dedicated deployment.

Your perimeter, your data

Browsing history, scraped pages, agent traces — all stay inside your VPC. Ollagraph the company never sees a customer URL.

You hold the keys

TLS 1.3 in transit, AES-256 at rest, customer-managed keys via AWS KMS, GCP KMS, or Azure Key Vault. Rotate on your schedule.

SSO, SCIM, RBAC

SAML 2.0 with Okta, Entra, Google. SCIM 2.0 provisioning. Fine-grained role bindings down to a single workspace, agent, or key.

BYO cloud, BYO proxies

Deploy into AWS, GCP, or Azure. Plug your residential proxy fleet into the renderer. Cap egress by IP, by workspace, by job.

Audit log to your SIEM

Every API call, every agent action, every key event. Stream straight to Splunk, Datadog, Snowflake. Field-level redaction policies enforced server-side.

Direct line to the team

Private Slack channel with the engineers who built it. We don't have a layer of CSMs between you and the code.

DEPLOYMENT

Three shapes. Same Ollagraph.

Pick the tenancy model that fits how your security team works. Whatever you choose, the API, MCP server, and SDKs behave identically.

SHARED

Multi-tenant cloud

The default. You sign up, you get a key, you start calling. Pooled compute, regional isolation, our keys.

· Pay-as-you-go credits
· Fastest to onboard
· Most customers start here
DEDICATED

Single-tenant cluster

Your own Ollagraph cluster in the region of your choice. Zero shared compute or egress. Customer-managed keys by default.

· Pick any AWS, GCP, Azure region
· Customer-managed keys
· Private peering on request
SELF-HOSTED

BYO cloud

We ship Helm charts and Terraform. You run it in your VPC. Data never leaves. Air-gapped variants on request.

· Helm chart + Terraform module
· Air-gap deployment supported
· Your SRE owns the cluster
REFERENCE ARCHITECTURE · BYO CLOUD
Your tenants
agents (SDK)
internal apps
MCP servers
SIEM / log sink
Ollagraph control plane · your VPC
api & auth
og-api
crawl + render
og-fetcher
observability
og-trace
MCP proxy
og-mcp
queue / jobs
og-jobs
policy / RBAC
og-policy
Storage: your S3 / GCS · KMS: your CMK
External egress
open web targets
customer SaaS
your proxy fleet
partner MCP servers
signed mTLS egress-policed audit-stream → your SIEM
TALK TO US

Real engineer on the other end.

We answer hard architecture questions on the first call. No sales-engineering funnel, no demos that take a week to schedule. The first reply is from someone who can read the code.

30-min architecture call
Walk through your stack with the team
Helm chart + Terraform shared upfront
Your SRE can run a dry-deploy before you commit
Pilot in your VPC inside two weeks
Real cluster, real data, real decisions

We reply within one business day. By submitting you agree to our privacy policy.