Deployment {Options}
Deploy Pillar where your data lives: our managed cloud, your own cloud account or data center, or a mix of both.
Choose where Pillar runs
Three ways to run the same platform. Pick the one that matches where your data is allowed to go.
Managed Cloud
We run it for you. Every feature on day one, nothing to operate.
Self-Hosted
Runs in your own cloud account or data center. Your data never leaves.
Hybrid
Keep regulated workloads in-house and run the rest in our cloud, under one policy.
| Managed Cloud | Self-Hosted | Hybrid | |
|---|---|---|---|
| Where inspection runs | Pillar's cloud | Your cloud account or data center | Your environment for regulated workloads, our cloud for the rest |
| Where logs and findings live | Pillar's cloud | Your own databases, under your keys and retention | Split by workload |
| Who operates it | Pillar | Your platform team, with our engineers on hand | Both |
| Coverage | Every feature | Everything except adaptive guardrails | Every feature in the cloud; everything except adaptive guardrails in-house |
| Data sent to Pillar | Your AI traffic, processed in our cloud | None. Telemetry is opt-in | Only for the workloads you run in our cloud |
Your data stays in your environment
An AI security tool has to read every prompt, response and tool call to protect them. Self-hosted, Pillar does that inside your walls, so the security layer never becomes another company holding your data.
Prompts, responses, tool calls, sessions, findings and the full audit trail.
Software and detector updates, as versioned releases you roll out on your schedule.
Nothing by default. Telemetry is opt-in, and the few documented sign-in and configuration connections carry no AI traffic.
Core detection models run in your environment. Any detector that uses a large language model points at your own endpoint, or is switched off.
The whole platform, self-hosted
Self-hosting shouldn't mean giving up protection. The same platform our managed cloud runs, in your environment.
Self-hosted Pillar runs in production at enterprise customers today.
Clear security and risk review faster
No new data processor
Pillar supplies the software; your prompts and customer data stay with you.
Evidence you keep
A full record of every AI interaction, flagged prompt and blocked response, under your own retention.
Certified vendor
SOC 2 Type II and ISO/IEC 27001:2022. See the Trust Center.
Every connection documented
Your network team gets the complete list of outbound connections and what each one carries.
From scoping to production
Your platform team deploys Pillar with the same tooling it uses for everything else, and our engineers work alongside them from the first call.
Scope
We map which AI workloads stay in-house and which can use our cloud, plus your network and compliance requirements.
Install
Your team deploys Pillar in your cloud account or data center, with our engineers on hand.
Connect
Point your AI gateway, code repositories and device management at Pillar.
Go live
Start in monitor mode, then switch to blocking.
Deployment, answered
Can Pillar be deployed on-premise?
Yes. Pillar runs in our managed cloud, in your own cloud account or data center, or as a hybrid of both. Self-hosted deployments include runtime guardrails, AI discovery, red teaming and agentic endpoint security.
What data leaves my environment when Pillar is self-hosted?
No prompts, responses, logs or findings. Software and detector updates come in. Telemetry back to Pillar is off unless you enable it. A small number of documented outbound connections, for sign-in and configuration, carry no AI traffic.
Can Pillar run air-gapped?
Pillar runs in production with no data flowing back to Pillar, including fully air-gapped at a Fortune 300 manufacturer. What counts as air-gapped varies by organization. If your definition rules out every outbound connection, we scope the deployment with you.
Which features work self-hosted?
Runtime guardrails (including multi-turn analysis), AI discovery, red teaming, agentic endpoint security, the dashboard and audit trail, and SIEM and gateway integrations. Adaptive guardrails are available in our managed cloud only today. (as of October 2026)
Do Pillar's detectors send prompts to a third-party AI model?
Not when self-hosted. Core detection models run inside your environment. Any detector that uses a large language model can point at a model endpoint in your own account, such as Amazon Bedrock, or be switched off.
What infrastructure does self-hosted Pillar need?
A Kubernetes environment. Amazon EKS is the documented path and others are scoped case by case. You need at least three GPU-enabled nodes and two general-purpose nodes, plus your own PostgreSQL, Redis and Kafka for production.
How are updates delivered?
New detector models and fixes ship as versioned releases. Your team pulls and rolls them out on its own schedule, through your existing deployment tooling.
Can we start in the cloud and bring workloads in-house later?
Yes. Pillar's policies and detectors work the same way in both, so many customers run regulated workloads self-hosted and everything else in our cloud. Moving a workload is part of the architecture review.
See Pillar in action
We value your privacy. See our Privacy Policy for details.
In your 30 minute personal demo, you will learn how Pillar:
Seamlessly integrates with your code, AI and data platforms and provide full visibility into AI/ML assets.
Automatically scan and evaluates your AI assets for security risks.
Enables you to create and enforce AI security policies in development and runtime.
We've received your message, and we'll follow up via email shortly
.webp)
%20(1).webp)





