Where Averholm runs is a decision for your security committee, not a tier of the product. Both modes carry the same capabilities, the same version and the same roadmap — what differs is who holds the database, and who can reach it.
Most fiduciaires and CSPs are best served by the EU cloud. Self-hosting exists for firms whose policy or supervisor requires the data never to leave.
Hosted in the EU with EU sub-processors, isolated per tenant at the database layer, patched and upgraded continuously. Running the same day you sign.
The application and its database, in your datacentre or private cloud. There is no network route from us to your production — access is not a policy we promise, it is an absence we build.
The boundary is the same shape in both modes. The application reads the register and downloads the public sanctions and PEP lists over outbound connections your security team can allowlist. It does not upload client data anywhere, in either deployment. What changes between them is only whose boundary the database sits inside.
Cloud is the right choice for most firms — EU-hosted, isolated, audited. But a bank or a large fiduciaire with a hard data-residency policy shouldn't have to compromise. On-premises removes the question entirely: the data never leaves your control, because the software comes to it.
Client records, beneficial owners, screening decisions — all sit in your database, on your storage, encrypted with your keys. There is no vendor copy anywhere.
You don't have to take our word that we won't look. There's no network path from us to your production, and no telemetry that carries your data. The architecture makes access impossible, not merely prohibited.
It slots into the environment your security team already runs — your network segmentation, your identity, your backups, your change process. The application and its database, nothing exotic.
It's not a stripped-down fork. On-premises is the same Averholm — monitoring, screening, pKYC, cases, goAML — kept on the same version as everyone else.
We ship signed, versioned releases. Your IT deploys releases to production on your schedule and runs the database migrations. We are never in that path.
Sanctions and PEP lists update over an outbound connection you allowlist — a download, never an upload. No release needed to stay current, and no data leaves.
Under a support contract, we work only on your non-production environment. Issues are reproduced there, on data that has been anonymised on the way over from production.
The AI features are opt-in. The one that reasons about your customers runs against an endpoint you control — your own model — or stays off. Nothing confidential leaves your boundary.
Every record, beneficial owner, screening result and audit entry lives only in your own database.
Database credentials, encryption keys and data-source keys are held by you, injected via your own secret store.
Where any AI feature that touches customer data runs is your choice — your tenant model, an on-prem model, or off.
Application logs, the append-only audit trail and backups stay on your systems, under your retention rules.
The only thing that crosses your boundary is the outbound refresh of the public sanctions and PEP lists — a one-way download to endpoints your security team allowlists. Your data is never sent anywhere.
Most firms are best served by our EU cloud. On-premises exists for those whose policy or regulator requires it.
| EU cloud (managed) | On-premises (self-hosted) | |
|---|---|---|
| Where data lives | Our EU infrastructure, isolated per tenant | Your own datacentre / private cloud |
| Who can access production | Us, strictly, under the DPA | Only you — no vendor path |
| Who deploys releases | We do, continuously | Your IT, on your schedule |
| Support access | Our platform | Your masked test environment only |
| List updates | Automatic | Automatic (outbound download) |
| AI features | EU-hosted, human-reviewed | Your endpoint, or off |
| Best for | Most obliged entities | Banks, large fiduciaires, strict data-residency |
| Setup | Minutes | A scoped enterprise engagement |
We'll walk through the deployment model, the data flows and the controls — and scope an on-premises engagement to your environment.