Skip to content

Customer-controlled deployment

Self-hosted enterprise AI: who runs what

Run Marella AI on infrastructure your organisation controls, then write down who owns the updates, the backups and who can reach the system.

Updated 21 Aug 2026

Definition

Self-hosted describes where the software package runs. It does not by itself establish local models, air-gapping, on-premises operation, residency or who can access each subsystem.

01

When self-hosting fits

Consider it when infrastructure control, network policy, approved services or data-location requirements cannot be met by the proposed managed boundary and the organisation can own the added operations.

  • Customer-controlled infrastructure
  • Specific network and egress policy
  • Approved storage and model path
  • Internal operations capability
02

When managed deployment is better

A managed path may fit when the vendor's documented data boundary meets the requirement and the organisation does not want to own deployment, upgrades, monitoring, backup and incident response.

  • Documented data boundary suffices
  • No wish to own deployment
  • Avoid upgrades and monitoring
  • Avoid backup and incident response
03

Implemented package

A Docker-based self-hosted package exists in the product implementation. The production topology, supported services, model configuration and customer prerequisites require architecture and release review.

  • Application and worker services
  • Database and object-storage dependencies
  • Model and provider configuration
  • Identity, secrets and network configuration
04

Architecture proof

Review the package and a proposed data-flow diagram, then test installation, identity, retrieval, backup, recovery, upgrade and restricted-egress behaviour in a representative environment.

  • Dependency and image inventory
  • Ingress and egress matrix
  • Support-access route
  • Recovery and upgrade rehearsal
05

Shared responsibility

Put a name against each operational job, from patching the servers to answering an incident at two in the morning. Put exceptions in writing.

  • Infrastructure and application operation
  • Monitoring and vulnerability remediation
  • Secrets, backups and incidents
  • Support access and upgrades

What this page does not prove

  1. B1Self-hosted does not automatically mean on-premises, fully local or air-gapped.
  2. B2A local model path is configuration-specific and may change capability or support.
  3. B3Customer control also creates customer operating responsibilities.
  4. B4Do not infer a service level, topology or residency without written scope.

Frequently asked questions

Can Marella run with local models?

Self-hosted and local are different properties: self-hosted describes where the software package runs, while a local model means the inference itself runs on hardware you control. Marella's model and provider paths are configurable, and a fully local configuration needs architecture and release verification for the proposed models and workflow.

Is self-hosted the same as on-premises?

No. Self-hosted software may run in customer cloud or on customer premises. State the infrastructure and operator explicitly.

Who applies updates?

That responsibility depends on the support and operating model. Agree image delivery, testing, scheduling, rollback and vulnerability response before production use.

Review the operating model before the topology

Share the non-confidential infrastructure constraints and responsibility questions that the architecture must answer.