SaaS
Hosted by DigiUsher. Fastest time to value.
- First insight within 48 hours
- Shared multi-tenant infrastructure, hosted in EU, US, AUS and ME regions
- SOC 2 Type II and GDPR
Startups, scale-ups and growth-stage cloud-native teams.
Platform reference
DigiUsher runs as SaaS, as a dedicated single-tenant instance, or entirely inside your own cloud account under Bring Your Own Cloud, and the product surface is identical in all three.
You are not trading capability for control. The privacy posture is architectural rather than contractual: AI conversational content is dropped at the ingestion boundary by rule, whatever a connector is configured to send.
Pick the model that fits your regulatory posture. The product surface, the governed automation pipeline and the MCP endpoint behave identically across all three, so the choice is about where the data lives rather than what the platform can do.
Hosted by DigiUsher. Fastest time to value.
Startups, scale-ups and growth-stage cloud-native teams.
Single tenant in a region you pick. Your isolation, our operations.
Mid-market enterprise, EU data residency, regulated SaaS.
DigiUsher runs entirely inside your AWS, Azure, GCP, OCI or data center account. No cost, usage, telemetry or workload data leaves your infrastructure.
Banking, insurance, public sector.
Your cloud account
VPC · cost data · usage logs · billing exports · k8s metrics
Control plane
Metadata only · dashboards · forecasts · alerts
Under BYOC the whole platform, control plane included, runs inside your perimeter. Individual-level views are RBAC-gated, with an organization-wide aggregate-only mode for works-council and compliance postures. There is an audit record of every connector, credential and visibility change.
Ingestion, the FOCUS store, allocation, dashboards, the MCP endpoint, your keys and the audit log all run in your own account. The only traffic that crosses the boundary is software updates, inbound.
The distinction between a software provider and a data processor is not lawyer-speak. It determines which review path your procurement team has to walk.
| Regime | Concern it raises | How BYOC answers it |
|---|---|---|
| FCA / PRA (UK) | Outsourcing and third-party risk in material arrangements; operational resilience. | No data processing outside the firm's own perimeter, so DigiUsher is assessed as software supply rather than critical outsourcing. |
| DORA (EU) | ICT third-party risk register, exit strategy, subcontracting transparency. | FOCUS-native data stays in your estate and is standard-conformant, so exit is a data export you already own rather than a migration project. |
| MAS TRM (Singapore) | Data locality and cloud outsourcing controls for financial institutions. | Deployment inside the institution's own approved cloud account; no cross-border transfer introduced by the tool. |
| FedRAMP / IL2–IL4 (US) | Authorized boundary and government data handling. | BYOC runs within your existing authorized boundary rather than requiring a new external service to be authorized. DigiUsher holds no FedRAMP authorization of its own. |
| Works councils (DE/EU) | Individual-level monitoring of employee activity. | Organization-wide aggregate-only mode disables individual attribution views entirely; individual views are otherwise RBAC-gated. |
This table maps the concerns these regimes raise onto the BYOC deployment model. It is not a claim of certification, authorization, or approval under any of them: BYOC makes DigiUsher a software provider rather than a data processor, which is what simplifies your vendor risk assessment.
Attestations, subprocessors and document requests live in the Trust Center →
Three, at full feature parity: SaaS, a dedicated instance and Bring Your Own Cloud. The product surface, the governed automation pipeline and the MCP endpoint behave identically across all three, so you are not trading capability for control.
No. The entire platform, control plane included, runs inside your own cloud account or data center, and no cost, usage, telemetry or workload data leaves that perimeter. DigiUsher is therefore assessed as a software provider rather than a data processor, which materially shortens third-party risk assessment under FCA, PRA, MAS, DORA, FedRAMP and IL2/IL4.
EU, US, Australia and Middle East hosted regions. A dedicated instance pins a single-tenant deployment to a named region of your choosing. Under BYOC, residency is determined solely by where you choose to run the software.
No. AI conversational content (prompts, responses and tool payloads) is dropped at the ingestion boundary by architectural rule rather than by configuration, so it cannot be retained even if a connector is misconfigured.
Yes. Individual views are role-gated by default, and an organization-wide aggregate-only mode disables per-person attribution entirely, the posture most works councils and EU employee-monitoring agreements require.
Via Terraform or Helm through your own CI/CD. BYOC is a deployment option within the Enterprise tier rather than a premium SKU, so feature parity does not mean paying extra to keep your own data. The support and maintenance model differs, which is set out on the pricing page.
44 more answers: TVR, FinOps, AI cost, Kubernetes, allocation and vendor selection →
15 minutes on the deployment model, the regulatory posture, and how governed automation fits your change process.