Deployment & Sovereignty
Your platform, your scope, your rules.
Banks, insurers and administrations cannot entrust their data to a shared service. beVault deploys wherever your constraints require: on-premises, in the cloud, in PaaS or in hybrid mode — with the same product in all cases.
The principle
The same product, in your environment
The constraint
Where components run is not a detail
For many organizations, the question isn't what the platform does but where it runs, who holds the access, and what leaves the network. That answer shapes the project timeline far more than the features do.
No capability is reserved for a specific deployment mode. The choice is an architecture decision, not a licensing tier — and it remains reversible: models and metadata are portable.
Deployment modes
On-premises, cloud, PaaS, or hybrid
beVault can be installed on-premises, in the cloud, in PaaS or in hybrid mode. It's the same product in all cases: what changes is the location of the components and who operates the infrastructure.
- 01
On-premises
Installation on your own infrastructure, for regulated or disconnected environments. Components and data remain within your network perimeter.
- 02
Cloud, in your account
beVault installs in your own cloud environment. Processes execute within the perimeter you define, and your security team maintains control over access.
- 03
PaaS
We operate the platform for you: updates, monitoring, backups, and support. Ideal for getting started quickly and staying focused on business value.
- 04
Hybrid
Distribution between your servers and a cloud environment, depending on component sensitivity and operational constraints.
Two distinct deployments
The platform on one side, generated structures on the other
Deploying beVault means installing the platform components — metaVault, States and Workers — in the environment you have chosen, with Docker as the deployment technology.
Deploying generated structures means applying the objects and code produced by the platform to your target database. The two operations are independent: the beVault installation mode does not determine the location of your target database.
Security & compliance
What Your CISO Will Verify
We have been preparing our clients' security files for over ten years, at dFakto, for demanding financial and public institutions.
- Encryption & isolation
- Encryption in transit and at rest, strict environment separation, vault-managed secrets, and key rotation.
- Identity and authorizations
- SSO/SAML integration, granular roles by project and domain, and the least-privilege principle applied down to API keys.
- Auditability
- Full log of accesses, model changes, and executions. Every published figure can be reconstructed to its date.
Le système de management de la sécurité de l'information de dFakto est certifié ISO/IEC 27001:2022 dans le périmètre certifié. Learn more about dFakto’s certification →
Sovereignty
Stay in control
You decide where components live, who opens access, and what leaves your network.
Frequently Asked Questions
Infrastructure: the decision points
Can we change deployment modes later?
Yes. Models and metadata are portable: migrating from the managed service to your own environment, or vice versa, does not put your Data Vault at risk.
Which target databases are affected?
The generated code applies to the target database you have selected: Snowflake, Amazon Redshift, Microsoft SQL Server, or PostgreSQL. Databricks, Microsoft Fabric, and Google BigQuery are coming soon.
What if we already use an orchestrator?
AWS Step Functions is supported as an external orchestrator: it triggers and supervises processing without being a target database.
How are updates handled?
In managed service mode, we apply them for you. In your environment, they are delivered as a validated release, deployable according to your change schedule.
Next step
