Skip to content

Deployment decision guide

Managed versus self-hosted enterprise AI

Who runs the servers, who applies the updates and where your data sits under each option, so a deployment is chosen on constraints not preference.

Updated 21 Aug 2026

Definition

In a managed deployment the vendor operates the agreed service boundary; in a self-hosted one the customer operates the environment and its named dependencies. Either way, someone has to own updates, support access, backup and recovery. The label alone does not say who.

01

Start with hard constraints

Write down your hard constraints before you compare anything on convenience.

  • Data classes and location
  • Approved cloud and model services
  • Identity and network policy
  • Recovery objectives and operator capability
02

Managed can fit

Choose a managed path when its documented data and support boundary meets the requirements and you would rather the vendor ran it.

  • Vendor-operated service
  • Agreed storage and inference path
  • Contracted support and incident route
  • Defined customer configuration duties
03

Self-hosted can fit

Choose customer-controlled infrastructure when hard requirements need it and the organisation can own the additional operational responsibilities.

  • Infrastructure and network control
  • Approved dependency and model path
  • Internal monitoring and recovery
  • Update and vulnerability process
04

Draw both data flows

Map source files, parsed text, embeddings, prompts, outputs, logs, backups, support and telemetry for each option. Name the operator and location at every node.

  • Source files and parsed text
  • Embeddings, prompts and outputs
  • Logs, backups and telemetry
  • Operator and location per node
05

Test operations, not only installation

Rehearse access changes, restricted egress, backup, restore, upgrade, rollback, support and an incident path before treating the deployment as ready.

  • Access changes and restricted egress
  • Backup and restore
  • Upgrade and rollback
  • Support and incident path

Deployment responsibility comparison

The contract and architecture you actually sign beat these typical patterns.

Scroll to see more

What this page does not prove

  1. B1Self-hosted is not synonymous with air-gapped, on-premises or local-model.
  2. B2Managed is not synonymous with one universal hosting region.
  3. B3Operational capability can be a harder constraint than infrastructure access.
  4. B4Verify the exact Marella release and support boundary.

Test the claim on your documents

Pick a real piece of work, agree what a good answer looks like, then go through the results together.