On-premise GRC platform and self-hosted compliance software
GRCLens runs inside your own data centre, your own cloud tenancy, or a compliant in-country region — so regulated evidence never leaves your control.
Why data residency decides GRC platform selection
A compliance platform is an unusual kind of system: the evidence it holds is, almost by definition, the most sensitive material an organisation has. Control gaps, audit findings, risk registers, penetration test reports, incident records. It is a precise map of where an organisation is weakest.
That is why data residency questions surface so early in GRC procurement, and why they stop so many deals. Government entities, defence suppliers, critical infrastructure operators, banks and healthcare providers frequently cannot place that material in a multi-tenant cloud in another jurisdiction — sometimes as a matter of law, often as a matter of contract, and occasionally simply because the board will not accept it.
Most modern GRC platforms are cloud-only. If your obligations rule that out, the tooling conversation ends before it starts, and the programme goes back to spreadsheets.
Three ways to run GRCLens
Fully on-premises
Deployed in your own data centre on your own infrastructure. No outbound dependency on our systems for day-to-day operation, and no customer data leaving your network perimeter.
Your private cloud tenancy
Deployed into your own Azure, AWS or other cloud subscription, in the region you nominate. You retain ownership of the subscription, the keys and the data.
Managed, in-country
Hosted by us in a compliant in-country region where local residency is required but you would rather not operate the platform yourself.
Architecture that supports self-hosting properly
Containerised deployment
- Container-based stack deployed with standard orchestration
- PostgreSQL with high-availability configuration
- Runs on standard Linux infrastructure
- No dependency on a vendor-controlled control plane
Data handling commitments
- Your data is never used to train AI models
- Tenant isolation at the database schema level
- Role-based access control with full audit trail
- Evidence and reports stay within your deployment
AI assistance that does not export your evidence
AI features are usually where data residency promises quietly break down. A platform can be hosted in your region and still send every document to a third-party model endpoint somewhere else.
GRCLens includes an AI agent that reviews compliance evidence and recommends an approve or reject decision with a confidence score, while a person always makes the final call. Where your obligations require it, the AI components can be configured so that inference stays within your chosen boundary. If you are assessing a GRC platform against data residency requirements, ask every vendor specifically where AI inference happens — not just where the database sits.
Self-hosted GRC: frequently asked questions
Is the on-premises version a reduced edition of the product?
No. The self-hosted deployment runs the same application as our hosted environment, including the framework modules and the AI review agent. It is a deployment choice, not a feature tier.
What infrastructure do we need to provide?
A Linux environment capable of running a containerised application and a PostgreSQL database, with the sizing depending on the number of tenants, users and evidence volume. We size it with you before deployment rather than quoting a generic figure.
Who applies updates in a self-hosted deployment?
That depends on the arrangement. Some clients apply releases themselves on their own change schedule, which is usually the point of self-hosting. Others ask us to manage upgrades under a support agreement.
Can we start hosted and move on-premises later?
Yes. Organisations often pilot in a hosted environment and move to their own infrastructure before putting regulated evidence into the platform. Plan the migration before the pilot data becomes production data.
Talk to us about deployment
Tell us what your residency obligations actually say and we will tell you plainly whether GRCLens fits — including where it does not.
Contact us