Deployment options
Workforce Observatory runs where your data policy requires — private cloud, on-premises or fully air-gapped. Same platform, same governance controls.
Private cloud (your VPC)
- Runs in your AWS, Azure or GCP account — your network, your keys, your perimeter.
- Containerized deployment on Kubernetes or Docker Compose.
- Outbound connectivity limited to your approved endpoints.
Self-hosted / on-premises
- Installs on your own hardware or data center.
- PostgreSQL plus object storage — no managed-cloud dependency.
- Your backup, DR and retention policies apply end to end.
Air-gapped environments
- Delivery for networks without internet access.
- Artifacts shipped as signed containers and offline bundles.
- Updates applied manually, under your change control.
What we need from you
- A Kubernetes cluster or a Docker-capable VM.
- Access to your corporate identity provider (OIDC; ADFS/Keycloak supported).
- Reachable HR data sources (SFTP, databases or APIs).
What we handle
- Connector setup, schema mapping and the first governed metrics.
- Database migrations and upgrade path on every release.
- A pilot on your real data before any rollout decision.
Data residency
- All processing happens inside your chosen region and perimeter.
- No vendor-side telemetry; connector secrets stay server-side.
- GDPR-first design: aggregation thresholds and pseudonymization built in.
Discuss your deployment constraints
A 30-minute call to map your infrastructure, identity setup and data sources.