Enterprise
Snyte ships as containers with the deployment files committed to the repository. There is no Snyte-operated cloud to review, because every path is one you run. That is a constraint as much as a feature, and this page says what each path asks of your team.
Deployment models
Pick one to see the files involved and what your team is responsible for.
One host running Docker Compose. The right shape for a pilot that has to sit inside your network, or for a department-scale deployment with a bounded user group.
In the repository
Docker ComposeRepository
A reviewer can read the deployment instead of taking a description of it on trust. Every file named below exists at the path shown.
Multi-stage builds. The API image is distroless and runs as a non-root user; the web image runs as a dedicated user. Resource limits are set on every container.
Deployments for the API and web, horizontal autoscaling, ingress, network policy, an ExternalSecret example, and a bootstrap job that runs migrations before traffic. A Helm chart carries staging and production values.
A full single-host stack, a bundled install with a bootstrap job, a prebuilt-image variant for external data stores, and an opt-in monitoring stack.
The self-hosting runbook covers the dedicated single-organization install and the environment it needs. Deployment and production checklists sit beside it.
Identity and audit
Four mechanisms, each traceable to code. The gaps are listed beside them, because a review goes faster when the vendor names them first.
01
Tokens are validated against WorkOS AuthKit using JWKS-based RS256. TOTP two-factor is available with session expiry and revocation.
02
An unrecognised auth type returns 503 rather than letting the request through. The default is to refuse, not to allow.
03
Every query is scoped to the caller's organization in the application. On the decision tables, Postgres enforces that scope again with row-level security.
04
Access, authentication, and security events are written to one log and queryable per user, per organization, and system-wide.
Stated plainly
Procurement
Each one is published, not sent on request. Read them before the demo and the demo can be about your sources instead of our paperwork.
Not claimed
Next
A demo runs one of your questions against one of your sources, with your reviewers watching the trace. If the path holds up, the rest of the evaluation is a conversation about where it runs.