Deployment
What is Self-Hosted / On-Premises?
Running the tool on infrastructure you control, so source code never leaves your environment.
Self-hosting keeps code inside your perimeter. For defence, finance, healthcare and anyone with a hard data-residency rule, it is frequently the only deployment that passes review, which makes it a hard filter rather than a preference.
The cost is ownership: you run the upgrades, the database, the scaling and the incident response. Check carefully whether a vendor's self-hosted edition is a first-class product or a legacy option kept alive for existing customers, because those age very differently.
Top 16 Self-Hosted / On-Premises tools
Every tool in the directory documented as supporting Self-Hosted / On-Premises, 10 fully, 6 partially, with what its own documentation says.
Support is not the same as parity, since some implementations are narrower in scope, gated to a higher plan tier, or maintained only for existing customers. The note under each tool is what its own documentation describes.
- 1
On-prem code/container scanning from Pro; Zen Firewall on-prem and endpoint agent need Advanced
- 2ChatGPT / CodexAgent Coding Tool
Codex CLI --oss mode runs against buyer's own Ollama/LM Studio or any OpenAI-compatible endpoint.
- 3
Enterprise Plan only: full on-prem/VPC deployment (AWS/GCP/Azure or private data center)
- 4
Container image runs in customer infra; Enterprise only, 500-seat minimum.
- 5
On-prem (Self managed) deployment listed on all three paid tiers: Standard, Pro, Enterprise
- 6
Full Enterprise Server platform installs into customer VPC or datacenter via standalone or existing Kubernetes.
- 7
GitHub Enterprise Server is customer-installed; Code Security and Secret Protection sold as standalone SKUs since 3.17.
- 8
docker-compose on customer compute; buyer provisions Postgres with pgvector and Redis.
- 9
Documented Kubernetes install, images via Replicated registries.
- 10SonarQubeQuality Platform
SonarQube Server self-managed; free Community Build; Data Center edition for large enterprises.
- 11
On-prem CxSAST installs in customer infrastructure, SAST only; the Checkmarx One platform stays vendor-hosted.
- 12
Buyer runs runners executing cloud sessions in own network; control plane and inference stay with Anthropic.
- 13
Only the Fair Source CLI runs locally; Qlty Cloud platform and dashboard are SaaS-only.
- 14
OSS engine runs in customer CI; platform stays SaaS. Enterprise adds Semgrep-managed tenant, not customer install.
- 15
Broker Client and Container Registry Agent deploy in customer infra; Broker Server and scanning stay Snyk-hosted.
- 16
SCA and CI agents run in customer network; analysis platform and results remain Veracode SaaS.
What to look for
- Whether the self-hosted edition reaches feature parity with the cloud one
- Whether it is actively developed or maintained for legacy customers only
- Infrastructure requirements and realistic operational burden
- How vulnerability and rule updates reach an installation you control
Related terms
FAQ
What is Self-Hosted / On-Premises?
Running the tool on infrastructure you control, so source code never leaves your environment.
How many tools support Self-Hosted / On-Premises?
16 of the 20 tools tracked in this directory support Self-Hosted / On-Premises, 10 fully and 6 partially, including Aikido, ChatGPT / Codex, CodeAnt AI, CodeRabbit, CodeScene. Support is not the same as parity, since some implementations are narrower in scope, gated to a higher plan tier, or maintained only for existing customers. The note under each tool is what its own documentation describes.
What should you look for in Self-Hosted / On-Premises?
Whether the self-hosted edition reaches feature parity with the cloud one. Whether it is actively developed or maintained for legacy customers only. Infrastructure requirements and realistic operational burden. How vulnerability and rule updates reach an installation you control.