# Enterprise Deployment & Security

Enterprise-grade deployment from fully managed SaaS to air-gapped on-premise. Deploy Picsellia where your data lives, with ISO 27001 security and fine-grained access control.

## Deployment Options

### Deploy where your data lives

Choose the deployment model that fits your security requirements and infrastructure.

#### SaaS
- Fully managed cloud platform
- Get started in minutes
- Zero infrastructure management
- Automatic updates & patches
- Built-in redundancy & backups
- ISO 27001:2022 certified
- EU & US data centers
- Instant provisioning

**Best for:** Teams who want to focus on ML, not infrastructure

#### Hybrid
- Your data, our platform
- Best of both worlds
- Connect your own storage (S3, GCS, Azure)
- Use your GPU compute resources
- Bring your Docker registry
- Data never leaves your infrastructure
- Picsellia manages the control plane
- Seamless integration

**Best for:** Organizations with existing cloud infrastructure & data residency requirements

#### On-Premise
- Full control, your infrastructure
- Maximum security & compliance
- Kubernetes (Helm charts)
- Docker Compose deployment
- Air-gapped environments supported
- Deploy on any cloud or bare metal
- Full network isolation
- Custom security policies

**Best for:** Enterprises with strict compliance requirements or air-gapped environments

## Hybrid Architecture

### Connect your infrastructure

Keep sensitive data in your environment while using Picsellia's managed control plane. Connect your storage, compute, and container registry directly.

#### Cloud Storage
- AWS S3, Google Cloud Storage, Azure Blob

#### GPU Compute
- Your AWS, GCP, or Azure GPU instances

#### Docker Registry
- ECR, GCR, ACR, or private registries

## Architecture Overview

Your Infrastructure
- Storage
- Compute
- Registry
- Picsellia Control Plane
  - UI & API
  - Orchestration
  - Monitoring
  - Metadata

Your data never leaves your infrastructure

## Complete On-Premise Solution

Run the entire Picsellia MLOps platform on your own infrastructure. Full data sovereignty, air-gapped capable, with enterprise-grade support included.
- Kubernetes & Docker
- Air-Gapped
- Bare Metal
- Custom SLAs
- SSO / SAML
- Full Isolation

### Kubernetes
- Deploy with Helm charts on any Kubernetes cluster
  - `helm install picsellia`

### Docker Compose
- Simple deployment for smaller teams
  - `docker-compose up -d`

Air-gapped support
- Full offline installation available. Container images and charts can be transferred via secure media for isolated environments.

## Full control on your infrastructure

Deploy the complete Picsellia stack in your own data center or private cloud. Support for Kubernetes clusters or simple Docker Compose setups.
- Deploy on AWS, GCP, Azure, or bare metal
- Full network isolation & firewall control
- Custom SSL certificates
- Integration with internal identity providers
- Your backup & disaster recovery policies

#### Dedicated Support
- Named customer success manager, priority SLAs, and direct engineering access

#### Custom Integrations
- Connect with your existing CI/CD, identity providers, and monitoring stack

#### Training & Onboarding
- White-glove onboarding, team training sessions, and ongoing enablement

## Enterprise-grade security standards

Picsellia meets rigorous security and compliance requirements for enterprise deployments.

### ISO 27001:2022
- International standard for information security management

### GDPR Compliant
- EU data protection & privacy standards

### Data Encryption
- AES-256 at rest, TLS 1.3 in transit

### SSO / SAML
- Enterprise identity provider integration

#### Audit Logs
- Complete activity tracking for compliance and forensics

#### API Key Management
- Scoped tokens with expiration and revocation

#### IP Allowlisting
- Restrict access to trusted networks

#### 2FA / MFA
- Multi-factor authentication for all users

#### Data Isolation
- Tenant separation at storage and compute level

#### Backup & Recovery
- Automated backups with point-in-time recovery

## Role-based access control

Fine-grained permissions at every level. Control who can access what, from organization-wide settings down to individual projects.

### Organization Level
- Owner: Full administrative control, billing, user management
- Admin: Manage users, workspaces, and organization settings
- Member: Access assigned workspaces and projects

### Workspace Level
- Manager: Create projects, manage workspace members
- Contributor: Edit projects, datasets, and experiments
- Viewer: Read-only access to workspace resources

### Project Level
- Lead: Full project control, manage collaborators
- Editor: Modify datasets, run experiments, deploy models
- Annotator: Label data within assigned campaigns
- Reviewer: Review and approve annotations

### Custom roles coming soon
- Create custom roles with granular permission sets tailored to your organization.

## Ready to discuss your enterprise deployment?

Our enterprise team can help you choose the right deployment model, answer compliance questions, and design a custom solution.
