Skip to main content Announcing Tool Gateway MCP: the universal MCPRead the announcement

Deployment · Data residency and self-hosting. Run StackOne in our cloud, a dedicated account or yours.

Compare shared cloud, a dedicated account and self-hosting for your AI rollout.

01

Shared cloud

StackOne runs outside your perimeter, in StackOne cloud, shared with other customers.

Encryption keyOurs or yours

StackOne hosts and operates the service.

Choose a region for each project
02

Dedicated account

StackOne runs outside your perimeter, in a StackOne cloud account that serves only your organization.

Encryption keyOurs or yours

An environment dedicated to your organization.

Agree region and operating arrangements
03

Self-hosted

StackOne runs inside your perimeter, on AWS, Google Cloud, Microsoft Azure, Oracle Cloud, Rackspace or any Kubernetes-compatible environment.

Encryption keyYours

Your team operates StackOne in your environment.

Separate licence and support agreement

Data residency by region. Choose a region for each project.

Create a managed-cloud project in Ireland, Belgium or Northern Virginia, with other regions on demand.

Separate teams or customers by project. Each project holds its own connected accounts and credentials, with access assigned inside it.

Explore Connector Access
Northwind Projects New project
Project nameEU Operations
Region
  • AWS Europe (Ireland)
  • Google Cloud Europe (Belgium)
  • AWS North America (United States)
  • AWSGoogle CloudAnother regionOn demand

The location where your data will be stored and processed. More about regions An organization can have several projects, each in its own region.

Self-hosted deployment. Run StackOne in your own infrastructure.

StackOne supplies the releases, connector updates and security patches. Your team runs the environment.

Kubernetes and Helm packaging, with Terraform for infrastructure setup.

Plan and deploy with StackOneInfrastructure requirements · deployment guidance
StackOne
Ongoing delivery
  • Additional connectors
  • Connector updates
  • New features
  • Security patches
Releases
Your infrastructure
Run by your team
  • Install and configure
  • Operate and monitor
  • Apply updates
  • Manage backups
Agreed support from StackOne

Self-hosted architecture. How a self-hosted deployment fits together.

StackOne runs inside your environment, and every endpoint can stay behind your VPC. Calls go straight from your deployment to each business system.

Private network / VPC
Your environmentYour cloud account or Kubernetes cluster AWSGoogle CloudAzure Kubernetes
Your apps and agents
  • Users in the browser
  • Your application
  • AI agents
Business systems
  • Workday
  • Salesforce
  • NetSuite
  • ServiceNow
  • Slack
StackOne
  • API
  • MCP
  • Connection UI
  • Workers

All StackOne endpoints stay inside your network

Secret manager
Runtime secrets and the encryption key
PostgreSQL
Provider credentials Encrypted
App stores and logs
Configuration, sync data, caches, queues and logs
HTTPS over your network
API calls and OAuthDirect to each provider
Encryption key
Ciphertext
App data
Optional services
Off
Telemetry, AI and analytics

Customer data and provider credentials don't pass through StackOne's hosted service.

Available on Enterprise with a self-hosting licence. Get a demo

Credential encryption and BYOK. Choose who manages the encryption keys.

Protect stored connector credentials with StackOne-managed keys or your own.

  1. 1

    Pick the key

    StackOne-managed or Your own key
  2. 2

    Credentials stay encrypted

    Connector credentialsStored encrypted for each connected account
  3. 3

    StackOne authenticates the call

    Your agent never needs the credential.

IP allowlisting. Restrict dashboard and API access by source IP.

Allow single addresses, ranges or CIDR blocks for each project.

Allowed addresses 3 rules
  • 203.0.113.41 Single address Frankfurt office
  • 198.51.100.0-198.51.100.63 Range Backend servers
  • 192.0.2.0/24 CIDR block Corporate NAT gateway

Unlisted address

Source IP203.0.113.200

403Refused by the IP restriction

Dashboard and API requests from outside the allowlist are refused.

SOC 2 Type II security review. Evidence for your security review.

"When you're able to clearly show that data sharing is limited, it makes such a smooth security review phase to get through with our customers."
KlausCTO, Introist
Read the Introist story

SOC 2 Type II

Request the report, and review subprocessors and security information, in our trust centre.

Visit the trust centre

FAQ. Questions about deployment and data residency

Plan your StackOne deployment.

Talk through regions, key ownership and support for your environment.