One platform. Three ways to run it.
Start on the managed platform in minutes. Move to an AWS account dedicated to you—provisioned and operated by us—when you outgrow it. Take the whole thing in-house whenever you want. Same open-source software, same public API, and integrations that never notice the move.
Pick where it runs
The three modes are a ladder, not a menu. Most customers land on the managed platform, move to a Dedicated Deployment when their scale, identity or procurement requirements call for one, and keep the option to take the account with them.
Managed Platform
Your graphs run on our multi-tenant platform, each in its own isolated graph database. Sign up, connect QuickBooks or the SEC repository, done.
- Price
- From $99 per graph per month
- Paper
- The public Terms — or our hosted MSA plus a one-page Order Form when procurement asks
Dedicated Deployment
The same platform, provisioned into an AWS account dedicated to your organization inside our cloud organization, off the same assembly line as our own production. Account-level isolation. Sign in from your identity provider and provision users from it. Read-only visibility into the account, always.
- Price
- AWS at cost, plus an operations fee and an annual platform fee — quoted per engagement
- Paper
- MSA + Order Form, Schedule B
Self-Hosted
Clone the Apache-2.0 repository and bootstrap it into your own AWS account. You hold the root, the data, and the audit. Support, advisory and integration work are available from Harbinger FinLab — through the public API, with a key you issue and can revoke, never from inside your account.
- Price
- Free to run. Services priced per engagement
- Paper
- None required to run it. Services under a Harbinger MSA and a SOW
Running many entities or clients? Start the conversation early—every graph beyond your first is a routine lift on the managed platform, and at scale a Dedicated Deployment is usually the better fit.
Side by side
Who owns what, who operates what, and what each mode means for your data, your sign-in and your exit.
| Managed Platform | Dedicated Deployment | Self-Hosted | |
|---|---|---|---|
| Who owns the AWS account | RoboSystems | RoboSystems — an account dedicated to you | You |
| Who operates it | RoboSystems | RoboSystems | You |
| Who holds your data | RoboSystems | RoboSystems, in your account only | You — we never hold it |
| Isolation | Your own graph database per subscription | Your own AWS account | Your environment |
| How you sign in | Email and password, with passkeys as a second factor | Your identity provider (OIDC SSO) with SCIM provisioning; passkeys | Whatever you configure — the same software |
| SEC repository | Add a subscription | Included through a managed-platform account | Rebuild from EDGAR with the open pipeline |
| Contract | Terms of Service, or MSA + Order Form | MSA + Order Form (Schedule B) | Apache 2.0; services via Harbinger FinLab |
| Attestation | SOC 2 Type II compliance in progress; the managed platform is inside the scope of the examination | Inside that scope for as long as we operate it | Your audit. You inherit the control design in the code and infrastructure — not our report |
| Leaving | Download backups; read everything through the public API | Account Transfer to your own ownership — a priced engagement, terms in the MSA from day one | Nothing to leave |
Identity & access
Sign-in from your identity provider, accounts provisioned and deactivated by it, passkeys as a second factor. SSO and SCIM are configured during onboarding of a Dedicated Deployment; they aren't offered on the managed platform.
Single sign-on
Sign in from your identity provider over OIDC. Identities link once to an account we provisioned — deactivate someone at your IdP and they're refused, valid token or not. Verified end-to-end against Okta; any OIDC-compliant provider.
SCIM 2.0 provisioning
Create, update and deactivate users from your identity provider. Deactivation revokes sessions and API keys immediately; delete is a deactivate, never destructive. Verified against Okta.
Passkeys & MFA
WebAuthn passkeys as a second factor or for passwordless sign-in, with single-use recovery codes. A deployment can require them for organization owners and admins.
Roles and scoped keys
Viewer, member and admin on every graph. API keys scoped to a single graph work on that graph's REST, GraphQL and MCP endpoints and are refused everywhere else.
One security program, every environment we operate
The managed platform and every Dedicated Deployment come off the same assembly line and run the same controls. What we claim about them is stated in the contract you sign and on the Trust Center—not only here—and we say “in progress” until the auditor says otherwise.
- Encryption in transit and at rest; every graph in its own database.
- Tenant isolation is tested, not asserted: an authenticated harness provisions two tenants against a live deployment and fires a cross-tenant and privilege-escalation matrix at it — REST, Cypher, GraphQL, MCP, both extension surfaces, both directions.
- A pinned supply chain: every CI action pinned to a commit, release deployments dispatch-only, provenance certified per pull request. Dedicated Deployments run a byte-identical, tag-pinned mirror of the public repository.
- Security incidents affecting your data: notice within 72 hours. Security releases: applied fleet-wide.
- SOC 2 Type II compliance is in progress with an independent CPA firm; the report will be available to customers under NDA once the audit is complete. Its scope is the environments we operate — the managed platform, and a Dedicated Deployment for as long as we operate it — never a self-hosted one.
Nothing held hostage
Every backup is a downloadable archive. Every graph is a remote MCP server and a public API. And a Dedicated Deployment can be transferred to your own AWS account through the Account Transfer engagement—terms in the MSA on day one, never negotiated under renewal pressure. You leave with the entire running system, in an account you own, still working; your integrations never notice, because they only ever spoke the public API.
How buying works
Managed
Sign up; the public Terms govern. Need paper? The MSA is public — a one-page Order Form incorporates it.
Dedicated
One conversation, one Order Form with Schedule B. Pricing is AWS at cost plus an operations fee and an annual platform fee; we don't mark up the cloud bill.
Self-hosted
No RoboSystems contract needed. Support and integration engagements are with Harbinger FinLab under its MSA and a SOW.