Averholm
Deployment · EU cloud or your own infrastructure

Two places the same product can live.

Where Averholm runs is a decision for your security committee, not a tier of the product. Both modes carry the same capabilities, the same version and the same roadmap — what differs is who holds the database, and who can reach it.

Your infrastructure, your keys We never see production data Self-contained · standard components
Side by side

The same product, two boundaries.

Most fiduciaires and CSPs are best served by the EU cloud. Self-hosting exists for firms whose policy or supervisor requires the data never to leave.

Managed · most firms

Our EU cloud

Hosted in the EU with EU sub-processors, isolated per tenant at the database layer, patched and upgraded continuously. Running the same day you sign.

DataOur EU infrastructure, fenced off per tenant, with integration tests proving one tenant cannot read another
AccessUs, strictly and audibly, under a data-processing agreement
KeysHeld and rotated by us, disclosed in the sub-processor record
UpgradesWe deploy them continuously; you are never on an old version
SetupMinutes
How we hold your data →
Self-hosted · banks, PSF, large groups

Inside your own walls

The application and its database, in your datacentre or private cloud. There is no network route from us to your production — access is not a policy we promise, it is an absence we build.

DataYour storage, your backups, your retention rules — no vendor copy anywhere
AccessOnly you. We have no path in, and support never touches production
KeysYours, injected from your own secret store
UpgradesYour IT, on your schedule, from signed and versioned images
SetupA scoped engagement with your platform team
Scope a self-hosted deployment →

The boundary is the same shape in both modes. The application reads the register and downloads the public sanctions and PEP lists over outbound connections your security team can allowlist. It does not upload client data anywhere, in either deployment. What changes between them is only whose boundary the database sits inside.

Why on-premises

The strongest answer to "where does our data go?" is: nowhere.

Cloud is the right choice for most firms — EU-hosted, isolated, audited. But a bank or a large fiduciaire with a hard data-residency policy shouldn't have to compromise. On-premises removes the question entirely: the data never leaves your control, because the software comes to it.

Data sovereignty, absolute

Client records, beneficial owners, screening decisions — all sit in your database, on your storage, encrypted with your keys. There is no vendor copy anywhere.

No trust required — by design

You don't have to take our word that we won't look. There's no network path from us to your production, and no telemetry that carries your data. The architecture makes access impossible, not merely prohibited.

Fits your existing controls

It slots into the environment your security team already runs — your network segmentation, your identity, your backups, your change process. The application and its database, nothing exotic.

Same product, same roadmap

It's not a stripped-down fork. On-premises is the same Averholm — monitoring, screening, pKYC, cases, goAML — kept on the same version as everyone else.

How it works

Operated by you. Supported by us — without ever touching your data.

You deploy

We ship signed, versioned releases. Your IT deploys releases to production on your schedule and runs the database migrations. We are never in that path.

Lists refresh themselves

Sanctions and PEP lists update over an outbound connection you allowlist — a download, never an upload. No release needed to stay current, and no data leaves.

Support on masked test

Under a support contract, we work only on your non-production environment. Issues are reproduced there, on data that has been anonymised on the way over from production.

AI on your terms

The AI features are opt-in. The one that reasons about your customers runs against an endpoint you control — your own model — or stays off. Nothing confidential leaves your boundary.

What stays in your infrastructure

Everything that matters.

All client & case data

Every record, beneficial owner, screening result and audit entry lives only in your own database.

Encryption keys & secrets

Database credentials, encryption keys and data-source keys are held by you, injected via your own secret store.

The AI endpoint

Where any AI feature that touches customer data runs is your choice — your tenant model, an on-prem model, or off.

Logs & backups

Application logs, the append-only audit trail and backups stay on your systems, under your retention rules.

The only thing that crosses your boundary is the outbound refresh of the public sanctions and PEP lists — a one-way download to endpoints your security team allowlists. Your data is never sent anywhere.

Cloud or on-premises

Two ways to run the same product.

Most firms are best served by our EU cloud. On-premises exists for those whose policy or regulator requires it.

 EU cloud (managed)On-premises (self-hosted)
Where data livesOur EU infrastructure, isolated per tenantYour own datacentre / private cloud
Who can access productionUs, strictly, under the DPAOnly you — no vendor path
Who deploys releasesWe do, continuouslyYour IT, on your schedule
Support accessOur platformYour masked test environment only
List updatesAutomaticAutomatic (outbound download)
AI featuresEU-hosted, human-reviewedYour endpoint, or off
Best forMost obliged entitiesBanks, large fiduciaires, strict data-residency
SetupMinutesA scoped enterprise engagement
What security teams ask

Straight answers.

Can you technically access our data if you wanted to?+
In a self-hosted deployment, no. In an on-premises deployment there is no network route from us to your production environment, and the software carries no telemetry that transmits your data. Support happens only on a separate, anonymised test environment. Access isn't a policy we promise — it's an absence we build. In the EU cloud the honest answer is different: our operations team can reach it, strictly and audibly, under the data-processing agreement, and every access is written to the append-only trail. Those are genuinely different answers — pick the deployment whose answer your policy accepts.
How do we get support if you can't see production?+
Under a support contract, we work on your non-production environment, which is refreshed from production through an anonymisation step that masks personal data. You reproduce or hand us the issue there, plus a diagnostics bundle scrubbed of personal data. It constrains how we help — deliberately — and that's the trade you're choosing.
Do the sanctions lists still stay current?+
Yes. The application fetches the public lists (EU, UN, OFAC, UK) itself over an outbound connection you allowlist — a download, not an upload. Staying current needs no software release and sends nothing out. Licensed feeds run under your own licence.
What about the AI features — do they send data out?+
The AI is opt-in. Features whose input is public (the regulatory radar) are safe anywhere. The one that reasons about your customers only runs if you point it at an endpoint you control — your own tenant model or an on-prem model — otherwise it stays off and the deterministic checks continue. Nothing confidential ever leaves your boundary.
What does it run on?+
The application and its database — self-contained, no exotic dependencies. It fits alongside what your platform team already runs (your identity, network segmentation, secret store, backups and change process).

Bring your security and compliance teams.

We'll walk through the deployment model, the data flows and the controls — and scope an on-premises engagement to your environment.

Talk to us