Cargovate Request a demo

Home  /  Documentation  /  Deployment

Documentation 04

Where it runs, and what that asks of you.

The same product in all three cases. What changes is who holds the machine and how much of the operating burden sits with your team.

Option 01Managed

Our cloud

We run it. You choose the region at the outset and your records stay in it. Updates, backups and monitoring are ours; the only thing your IT function has to do is decide who gets an account.

You provide
Nothing beyond your users.
Suits
Most operators, and every evaluation — start here and move later if you need to.
Option 02Self-hosted

Inside your estate

Cargovate runs on your own servers under licence, as a small set of containers alongside a PostgreSQL database. It is delivered as a signed release bundle: your team verifies the signature, loads it, and starts it. Upgrades are the same bundle, and a failed upgrade rolls back to the previous version.

You provide
A Linux host with a container runtime, and somewhere to keep backups.
Suits
Organisations whose data cannot sit with a third party.
Option 03Air-gapped

No network path at all

The same bundle, transferred on removable media. Once running, the deployment makes no outbound connection — not for licensing, not for telemetry, not to us. That is a property your own security team can verify from outside rather than take on trust, which is the point of it.

The functional cost is small and worth stating: features that inherently reach outside — third-party tracking feeds, email notification, blockchain anchoring — are unavailable because there is nowhere for them to reach. Everything else behaves identically.

You provide
A host, and a person to carry the media.
Suits
Defence, controlled-goods and classified environments.
All three

What does not change

The licence is the same whichever way you run it: the core, plus the modules you hold. An air-gapped installation is not a different product on different terms — it runs the same code from a signed bundle you copy in, and the only capability that genuinely needs a network is anchoring, which is optional. No deployment requires a blockchain. Anchoring is one optional capability, and a deployment without it keeps every record, every audit entry and every custody handoff — it simply cannot offer a third party independent verification of them.

Nor does any deployment phone home to stay alive. Software that stops working when it cannot reach its vendor is not something a regulated site can accept, and we do not ship it.

Next: access and audit

Security →