Deployment Options

One platform. Three ways to run it.

Start on the managed platform in minutes. Move to an AWS account dedicated to you—provisioned and operated by us—when you outgrow it. Take the whole thing in-house whenever you want. Same open-source software, same public API, and integrations that never notice the move.

See pricing

Pick where it runs

The three modes are a ladder, not a menu. Most customers land on the managed platform, move to a Dedicated Deployment when their scale, identity or procurement requirements call for one, and keep the option to take the account with them.

Self-serve · per graph

Managed Platform

Your graphs run on our multi-tenant platform, each in its own isolated graph database. Sign up, connect QuickBooks or the SEC repository, done.

Price
From $99 per graph per month
Paper
The public Terms — or our hosted MSA plus a one-page Order Form when procurement asks
NEW
Your own AWS account · operated by us

Dedicated Deployment

The same platform, provisioned into an AWS account dedicated to your organization inside our cloud organization, off the same assembly line as our own production. Account-level isolation. Sign in from your identity provider and provision users from it. Read-only visibility into the account, always.

Price
AWS at cost, plus an operations fee and an annual platform fee — quoted per engagement
Paper
MSA + Order Form, Schedule B
Your account · your operation

Self-Hosted

Clone the Apache-2.0 repository and bootstrap it into your own AWS account. You hold the root, the data, and the audit. Support, advisory and integration work are available from Harbinger FinLab — through the public API, with a key you issue and can revoke, never from inside your account.

Price
Free to run. Services priced per engagement
Paper
None required to run it. Services under a Harbinger MSA and a SOW

Running many entities or clients? Start the conversation early—every graph beyond your first is a routine lift on the managed platform, and at scale a Dedicated Deployment is usually the better fit.

Side by side

Who owns what, who operates what, and what each mode means for your data, your sign-in and your exit.

 Managed PlatformDedicated DeploymentSelf-Hosted
Who owns the AWS accountRoboSystemsRoboSystems — an account dedicated to youYou
Who operates itRoboSystemsRoboSystemsYou
Who holds your dataRoboSystemsRoboSystems, in your account onlyYou — we never hold it
IsolationYour own graph database per subscriptionYour own AWS accountYour environment
How you sign inEmail and password, with passkeys as a second factorYour identity provider (OIDC SSO) with SCIM provisioning; passkeysWhatever you configure — the same software
SEC repositoryAdd a subscriptionIncluded through a managed-platform accountRebuild from EDGAR with the open pipeline
ContractTerms of Service, or MSA + Order FormMSA + Order Form (Schedule B)Apache 2.0; services via Harbinger FinLab
AttestationSOC 2 Type II compliance in progress; the managed platform is inside the scope of the examinationInside that scope for as long as we operate itYour audit. You inherit the control design in the code and infrastructure — not our report
LeavingDownload backups; read everything through the public APIAccount Transfer to your own ownership — a priced engagement, terms in the MSA from day oneNothing to leave

Identity & access

Sign-in from your identity provider, accounts provisioned and deactivated by it, passkeys as a second factor. SSO and SCIM are configured during onboarding of a Dedicated Deployment; they aren't offered on the managed platform.

Single sign-on

Sign in from your identity provider over OIDC. Identities link once to an account we provisioned — deactivate someone at your IdP and they're refused, valid token or not. Verified end-to-end against Okta; any OIDC-compliant provider.

Dedicated Deployments

SCIM 2.0 provisioning

Create, update and deactivate users from your identity provider. Deactivation revokes sessions and API keys immediately; delete is a deactivate, never destructive. Verified against Okta.

Dedicated Deployments

Passkeys & MFA

WebAuthn passkeys as a second factor or for passwordless sign-in, with single-use recovery codes. A deployment can require them for organization owners and admins.

Managed platform and Dedicated Deployments

Roles and scoped keys

Viewer, member and admin on every graph. API keys scoped to a single graph work on that graph's REST, GraphQL and MCP endpoints and are refused everywhere else.

Every mode

One security program, every environment we operate

The managed platform and every Dedicated Deployment come off the same assembly line and run the same controls. What we claim about them is stated in the contract you sign and on the Trust Center—not only here—and we say “in progress” until the auditor says otherwise.

  • Encryption in transit and at rest; every graph in its own database.
  • Tenant isolation is tested, not asserted: an authenticated harness provisions two tenants against a live deployment and fires a cross-tenant and privilege-escalation matrix at it — REST, Cypher, GraphQL, MCP, both extension surfaces, both directions.
  • A pinned supply chain: every CI action pinned to a commit, release deployments dispatch-only, provenance certified per pull request. Dedicated Deployments run a byte-identical, tag-pinned mirror of the public repository.
  • Security incidents affecting your data: notice within 72 hours. Security releases: applied fleet-wide.
  • SOC 2 Type II compliance is in progress with an independent CPA firm; the report will be available to customers under NDA once the audit is complete. Its scope is the environments we operate — the managed platform, and a Dedicated Deployment for as long as we operate it — never a self-hosted one.

Nothing held hostage

Every backup is a downloadable archive. Every graph is a remote MCP server and a public API. And a Dedicated Deployment can be transferred to your own AWS account through the Account Transfer engagement—terms in the MSA on day one, never negotiated under renewal pressure. You leave with the entire running system, in an account you own, still working; your integrations never notice, because they only ever spoke the public API.

How buying works

Managed

Sign up; the public Terms govern. Need paper? The MSA is public — a one-page Order Form incorporates it.

Dedicated

One conversation, one Order Form with Schedule B. Pricing is AWS at cost plus an operations fee and an annual platform fee; we don't mark up the cloud bill.

Self-hosted

No RoboSystems contract needed. Support and integration engagements are with Harbinger FinLab under its MSA and a SOW.

Read the MSA