Cloud · On-Premise · Air-Gapped

Deploy on your terms.

VaultIQ runs wherever your security posture demands: fully managed in the cloud, self-hosted on your own infrastructure, or completely air-gapped. Moving off whatever you are on today is part of the engagement, not a separate project.

Choose your model

Three models. One platform.

Every deployment option delivers the same feature set, the same API, and the same experience. Choose the model that fits your organization’s requirements.

ON-PREMISE

Self-Hosted

Deploy VaultIQ on your own infrastructure with full control over data, networking, and compliance boundaries.

  • Docker or Kubernetes deployment
  • Full data sovereignty
  • Connect to your existing databases
  • Custom backup strategies
  • VPN and private network support
AIR-GAPPED

Air-Gapped

Purpose-built for classified and regulated environments that require complete network isolation.

  • Runs entirely disconnected from internet
  • Local AI models for OCR processing
  • USB-based update delivery
  • Military and government grade isolation
  • No external dependencies
Side by side

Compare deployment models

A detailed breakdown of capabilities across every deployment option so you can make an informed decision.

FeatureCloudSelf-HostedAir-Gapped
Automatic updatesManual or scheduledUSB delivery
Data locationAWS (multi-region)Your infrastructureYour infrastructure
AvailabilityProvider-managed, SLA by agreementSelf-managedSelf-managed
BackupAutomated (hourly)Custom strategyCustom strategy
AI / OCRCloud-hosted modelsCloud or local modelsLocal models only
Deployment timeInstant< 1 hour< 4 hours
MaintenanceFully managedYour teamYour team
Architecture

Built for portability from day one

VaultIQ’s containerized architecture means you can migrate between deployment models without data loss or downtime. Start in the cloud, move on-premise later, or run hybrid, your data stays portable.

Talk to an architect
VaultIQ Core
AWS / Cloud
On-Premise
Air-Gapped
Getting off the old system

You already have the documents. We move them.

Nobody buys a document system on a clean slate. There is a legacy EDMS, a decade of shared drives, or a registry that was scanned once and never indexed. Migration is part of every new engagement, not a professional-services upsell you discover later.

  1. 01

    Survey what you actually have

    Volume, formats, folder depth, and how much of it is images rather than text. This is also where the uncomfortable number usually appears: how many documents exist in more than one place, and which copy is authoritative.

  2. 02

    Map the old structure onto a file plan

    Existing folders become categories, existing conventions become metadata fields, and the values a clerk used to type become lookup sources. Agreeing this before the load is what separates a migration from a bulk copy.

  3. 03

    Load in bulk, then index

    Documents come in through the CLI importer or straight from an S3 or Azure bucket. OCR runs over anything that arrived as an image, and indexing templates apply metadata as each document lands, so the archive is searchable rather than merely present.

  4. 04

    Reconcile, item by item

    A reconciliation job compares what left the old system against what arrived. Mismatches are listed individually and resolved one at a time or in bulk, and an orphan check catches files that landed in storage without a record pointing at them. You get a number you can sign off, not an assurance.

  5. 05

    Attach retention and cut over

    Retention schedules apply to the migrated set, so inherited records enter their disposal clock properly rather than becoming a permanent archive by accident. The old system stays readable until you are satisfied, then it is retired.

Moving between our own deployments

The same tooling moves you cloud to on-premise, or on-premise to cloud, later on. Storage can be migrated between backends without touching the records, so switching from a local disk to S3, or from S3 to self-hosted MinIO, is an operational task rather than a second migration project.

What we need from you

An export from the incumbent system, or read access to where the files sit, plus whoever knows why the folders are named the way they are. That last one matters more than the first two, and it is usually the part that gets scheduled too late.

Ready to deploy VaultIQ?

Whether that is a managed cloud instance, a locked-down air-gapped installation, or moving a decade of records off the system you have now, we will scope it in writing before anyone signs.