Skip to main content
ZNYX AI

Deployment patterns

How to deploy an AI security platform while keeping data in your boundary.

The same security engine - the AI firewall, 40 detectors, agentic and MCP controls, output DLP egress gate, and evidence - runs on every tier. What changes across the three operating models is only placement and how your team operates: firewall only, firewall plus hosted control plane, and full private deployment. This page makes that boundary explicit so procurement and architecture reviews do not have to infer it from scattered copy.

Open Source

Self-hosted AI firewall plus guardrails.

  • The full security engine runs in your infrastructure
  • No control plane dependency to get protected
  • Local policy files and docs-based onboarding
  • Best for developer evaluation and small single-team rollouts

Growth

Self-hosted firewall with a hosted control plane.

  • The same security engine still runs in your infrastructure
  • Hosted control plane for policy workflow and operations
  • Metadata-first hosted visibility by default
  • Best for teams that need shared rollout and trace operations

Enterprise

Optional self-hosting for both firewall and control plane.

  • Private deployment for both firewall and control plane when required
  • Custom packaging, procurement, and deployment planning
  • Suitable for air-gap or security review constraints
  • Custom pricing and support model
The same security engine runs on every tier; only firewall and control plane placement change across Open Source, Growth, and Enterprise.
CapabilityOpen SourceGrowthEnterprise
Security engine (firewall, 40 detectors, agentic and MCP, output DLP, evidence)Same engineSame engineSame engine
Firewall locationCustomer infrastructureCustomer infrastructureCustomer infrastructure
Control plane locationNot applicableHosted by ZNYXHosted by ZNYX or customer infrastructure
Default hosted visibilityNot applicableOperational metadataDeployment-dependent
Who manages rollout workflowLocal teamShared team in hosted control planeShared team in hosted or private control plane
Typical buying triggerInitial evaluationOperational coordinationPrivate deployment requirement

Selection rule of thumb

You get the same protection on every tier, so the choice is about operations, not security coverage. Start with Open Source if the question is still "does the self-hosted firewall fit our app?" Move to Growth when the question becomes "how do multiple people manage rollout and operations?" Move to Enterprise when the question becomes "where is the control plane allowed to run?"

Secure every prompt, agent, and tool call, in your boundary.

Pull the open-source runtime, drop it into your stack, and start enforcing policy in minutes, free, forever. Add the hosted control plane when you want centralized policies, evidence, traces, and team workflows.