On-premise and air-gapped

Your cluster. Your data. Your rules.

Most regulated-data policies do not have a box for a multi-tenant SaaS. PharmaLogiks Enterprise is single-tenant and air-gap-capable: a Helm chart that deploys into your own infrastructure and, if you need it, never touches the internet at all.

Single-tenant by design

One customer, one deployment, one database. There is no shared backend and no multi-tenant data plane, so your shipment, custody and audit records never sit next to another company’s.

Zero egress by default

Nothing leaves your network unless you configure it to. Fonts are self-hosted, API docs are vendored, and AI inference runs locally, so an air-gapped install simply works.

Your infrastructure, your rules

It runs on your Kubernetes, your storage, your network policy and your identity provider. Data residency is wherever your cluster is, which is the answer most regulated-data policies actually need.

Local-first AI

Risk scoring, customs enrichment and breach prediction run on Ollama inside the cluster. You get the automation without shipping regulated data to a third-party model.

Why regulated teams cannot use most SaaS

When shipment records carry batch numbers, trial references, patient counts and custody history, they are exactly the data a regulated-data policy is written to protect. A multi-tenant cloud asks you to put that data on someone else’s infrastructure, next to other tenants, behind a control plane you do not run. For many hospitals, universities and pharma divisions, that is a hard stop before the evaluation even starts.

Being on-premise is not a deployment checkbox we added later. It is the architecture. See how that shapes the compliance model and the full platform.

PharmaLogiks admin console running inside a customer's own cluster, showing users, divisions and corridor rules

On-premise versus multi-tenant SaaS

DimensionTypical SaaSPharmaLogiks on-premise
Data locationVendor cloud, shared tenancyYour cluster, single tenant
Air-gapped operationNot possibleSupported, zero egress
AI inferenceVendor or third-party modelLocal Ollama, in-cluster
Update controlPushed by vendorYou validate and roll out
Data residencyVendor regionWherever your cluster runs
IdentityVendor SSO integrationYour SAML IdP and MFA

On-premise questions, answered

Genuinely on-premise and single-tenant. It ships as a Helm chart that deploys into your own Kubernetes cluster, on your storage and your network policy. There is no shared multi-tenant backend, and there is no vendor-hosted control plane your deployment depends on. A managed cloud option exists if you prefer it, but self-hosting is the default, not an afterthought.

See it live in 25 minutes.

Eight guided flows: compliance review, DPS screening, Part 11 e-signature, custody chain, breach prediction, GDPR erasure and the validation report. Then a 90-day pilot on your own programme, fully creditable.