Glyph can run as a managed service, in a private cloud tenancy, on-premises, or in an air-gapped environment. The deployment model determines who operates the infrastructure:
- Managed SaaS — Fortaify operates the website and control plane. Account and entitlement data is stored in the configured database; prompts and model traffic in the shipped client go to the model provider the user selects, not to Fortaify.
- Private cloud — the control plane runs in the customer's cloud tenancy. Deployment registration and heartbeat are implemented; heartbeat carries version and liveness metadata only.
- Self-hosted / on-premises — the customer operates the web, API, database, TLS, and backups. Outbound integrations (billing, email, telemetry, model metadata) are operator-configured and can be left disabled.
- Air-gapped — operated without a route to Fortaify; local inference continues to work, and updates and licensing use an offline process agreed per deployment. The air-gap mode blocks vendor and cloud model egress, downloads, and the heartbeat; operator-configured external integrations (for example an external OIDC provider or SIEM collector) are not blocked by the flag and must be left unset for strict zero egress.
Managed client policy enforcement is in development. See how Glyph Trust is designed to work and the Enterprise page for current availability.