Deployment options
Personal and sensitive data must be handled with the utmost care and Astralis is designed to ensure this in any configuration. This page outlines the Astralis deployment options to help you select the optimum configuration for your needs.
Comparing the three options
Astralis is available in three deployment options:
- Astralis Cloud: a fully managed, multi-tenant service hosted by Ethyca in our secure, SOC2-II certified infrastructure.
- Astralis Self-Hosted: deployed in your own cloud or on-premises, supported by Ethyca.
- Astralis Serverless: a dedicated, physically isolated instance that Ethyca manages for you, in the cloud provider and region you choose.
All three deliver the same platform. They differ in who operates it, how your instance is isolated from other customers, and where it runs.
| Astralis Cloud | Astralis Self-Hosted | Astralis Serverless | |
|---|---|---|---|
| Model | Fully managed, multi-tenant | Deployed inside your perimeter | Fully managed, dedicated single-tenant |
| Isolation | Logical separation between tenants | Full — you own the entire stack | Physical — an instance dedicated to you |
| Hosting | AWS, operated by Ethyca | Your cloud account or on-premises, via Docker image and Helm chart | Your choice of AWS, Azure or GCP; you select primary and backup regions |
| Operations | Zero DevOps | Your team patches, scales, tunes and upgrades | Zero DevOps; Ethyca scales elastically |
| Connectivity | Public endpoints | Air-gapped or restricted; opt-in outbound telemetry only | Private networking — VPC peering, VPC sharing or PrivateLink |
| Best for | Speed to value with minimal infrastructure management | Regulatory constraints that prohibit personal data leaving your boundary | Isolation and residency control without the operational burden |
Astralis Cloud
Astralis Cloud is hosted by Ethyca in our cloud infrastructure. By default, hosting is in the USA, with options available for organizations that require geographic data residency in Europe or other regions. Ethyca fully manages the infrastructure, operations and updates, and tenants are separated by strict logical isolation.
In the example below, you can see the typical configuration of Astralis Cloud which provides options to suit your preferred connectivity solutions:
Astralis Self-Hosted
Astralis Self-Hosted is a deployed instance of Astralis, installed in your cloud and secured by your organization's firewall. Ethyca has no access to this instance and no data is stored on Ethyca infrastructure. All data processing occurs in your cloud. Every component runs in your environment — the application on Kubernetes, its Postgres and Redis datastores, and the connectors to your data systems — and it can run fully air-gapped.
Your own DevOps and SRE teams provision, patch, scale, tune and upgrade the platform. That is the source of both the model's control and its operational burden.
Because Ethyca cannot see into your environment, Astralis offers an opt-in, outbound-only telemetry stream of sanitized logs and heartbeat metrics. It contains no personal data and grants Ethyca no inbound access, and exists to provide baseline insights for the Ethyca support team.
In the example below, you can see the typical configuration of Astralis Self-Hosted, where all Astralis tools are installed and configured within your cloud provider.
Astralis Serverless
Astralis Serverless gives you the isolation of self-hosting without the operational burden. Ethyca runs a dedicated, single-tenant instance for you — physically isolated from every other customer — and manages it end to end.
You choose the underlying cloud provider, AWS, Azure or GCP, to match your existing infrastructure, and you select the regions that meet your data residency and resiliency requirements. Ethyca connects to your environment over private networking such as VPC peering, VPC sharing or PrivateLink, which keeps traffic off the public internet and minimizes cloud egress costs.
In the example below, you can see the typical configuration of Astralis Serverless, where Ethyca operates the control plane in a dedicated cloud account and connects to your own VPC over a private network connection:
