Deployment model

Self-hosted vs hosted AI platforms — who runs the thing?

Running an AI operations platform yourself and buying it as a managed service are genuinely different trades: one costs you control, the other costs you operations capacity. This page states the trade honestly, then says where OperativeOps sits — self-hosted only, by design.

TL;DR
  • The question is not which model is better. It is who carries the operational load: a managed service carries it for you, self-hosting means your team carries it.
  • Managed services really are less work — no upgrades, no backups, no on-call. That is a genuine advantage, and it is worth paying for if you have no DevOps capacity.
  • Self-hosting wins where the data boundary is the requirement: regulated data, air-gapped networks, or a compliance programme you already own and would rather extend than replace.
  • Cost is rarely the tiebreaker in year one. Fixed self-hosted cost typically beats per-seat pricing only from about year three, and only if the operations team already exists.
  • OperativeOps is self-hosted only. There is no managed tenancy to start from or migrate to — if you need somebody else to run it, a managed competitor is the honest answer.

The trade, axis by axis

CriterionSelf-hostedManaged serviceGenerally favours
Data sovereigntyComplete. Data stays inside your network boundary — your keys, your logs, your audit trail.Contractual. Governed by a DPA and the provider's residency commitments. Strong on paper, but not under your control.Self-hosted
Operational burdenYours, indefinitely. Upgrades, backups, monitoring, patching and incident response are your team's standing job.The provider's. This is the single biggest and most honest advantage of a managed service.Managed
Time to first production useTypically 1–4 weeks, driven by your provisioning and security review rather than by the software itself.Hours to days. Sign up, connect SSO, start configuring.Managed
Compliance evidenceYour existing programme (ISO 27001, IT-Grundschutz, BSI C5) extends to the deployment. You own the evidence and the auditor talks to you.You inherit and review the provider's control mapping and certifications. Less work for you, less control for you.Depends
Cost shapeFixed: infrastructure plus roughly 0.25–0.5 FTE of operations. Stays flat as usage grows.Variable: per-seat or usage-priced. Cheap to start, grows with adoption.Depends
Model choiceAnything you can run or reach — local Ollama or vLLM on your own GPUs, as well as hosted model APIs.Whatever the provider has integrated. Fully local inference is rare inside a managed product.Self-hosted
Exit costLow. You already hold the data and the runtime; leaving is a configuration change, not a data migration.Depends entirely on export completeness and contract terms. Confirm the egress path before you commit.Self-hosted

Run it yourself when

  • Regulated data must not leave your network — BaFin-supervised financial services, MDR-regulated health, or public sector work with data localisation duties.
  • You already have a platform or DevOps team that can own upgrades, backups and on-call sustainably. Self-hosting without that team is how pilots quietly die.
  • You run an existing ISO 27001, IT-Grundschutz or BSI C5 programme and would rather extend your own compliance boundary than review somebody else's.
  • Air-gapped or partially air-gapped networks, where any external SaaS dependency is disqualifying however good the DPA.
  • You need local model inference — open-weight models on your own GPU hardware, with no prompt leaving the building.
  • The horizon is long (3+ years), so fixed infrastructure cost amortises better than per-seat pricing that scales with headcount.

Buy a managed service when

  • You have no DevOps capacity and no realistic plan to hire it. A managed product will serve you better than a self-hosted platform nobody has time to operate — that is the correct decision, not a compromise.
  • Time to value is the binding constraint: you need something live this week, not after a provisioning cycle and a security review.
  • EU-only data residency under a DPA satisfies your data protection officer, and processing inside your own network is not a hard requirement.
  • You are still proving the use case and would rather not spend infrastructure budget on an experiment.
  • Hosted model APIs cover your model requirements and no data classification forbids sending context to them.
  • Elastic scale matters more than control — traffic spikes should be somebody else's pager.

Where OperativeOps sits

OperativeOps is self-hosted only. It ships as software you deploy — Docker Compose on a single host, Kubernetes on-premises, or fully air-gapped — into infrastructure you already control. There is no managed OperativeOps tenancy: no environment operated on your behalf, and therefore no migration between deployment modes to plan for.

That is a deliberate constraint rather than a roadmap gap. Every design decision assumes the data plane is yours: your model endpoints and keys (OpenAI, Anthropic, Ollama, vLLM), your vector store, your systems reached over MCP, and an append-only audit ledger that lives in your database on your infrastructure.

It also means OperativeOps is the wrong answer for some readers. If there is nobody to operate a container platform and no path to getting one, everything above about managed services applies to you, and a managed competitor is the better choice. The trade is real, and pretending otherwise would not survive first contact with your operations team.

Frequently asked questions

Can I start on a hosted OperativeOps and move to self-hosted later?

No — there is no hosted OperativeOps to start from. It is distributed as self-hosted software only, so the single deployment path is into infrastructure you control. If the appeal of starting hosted was avoiding a commitment, the closest equivalent is a disposable deployment: one VM running Docker Compose, torn down when the evaluation ends.

What infrastructure does a self-hosted deployment require?

Minimum: a Linux host or a Kubernetes cluster with a container runtime (Docker or containerd), a PostgreSQL 15+ database, and — only if agents are configured to call hosted model APIs — outbound network access through the egress gate. Optional: one or more GPU-equipped nodes if you want local inference with Ollama or vLLM. Sizing is driven by concurrent users and the size of the retrieval corpus.

Can I run it without a Kubernetes cluster?

Yes. Docker Compose on a single adequately sized VM or dedicated server is a supported deployment mode and is sufficient for small and mid-sized deployments. Kubernetes is the better choice above that scale, or wherever high availability and rolling-update semantics are required. The same release runs in both modes.

Does self-hosting mean no data ever leaves my network?

Only if the model backends you configure run locally. Self-hosting controls where the platform and its data live; it does not by itself stop an agent from calling a hosted model API. If a hosted provider is configured, prompts and retrieved context go to that provider under its terms. Running Ollama or vLLM on your own hardware is what makes the boundary absolute — and the egress gate is where you enforce which of the two applies, per agent.

How much operational effort is a self-hosted AI platform, realistically?

Budget roughly a quarter to a half of a full-time engineer for a production deployment in steady state, on top of the initial provisioning and security review. That covers version upgrades, database backups and restore drills, certificate and dependency patching, monitoring, and incident response. It is not a full-time job, but it has to be somebody's named responsibility — self-hosted deployments fail when it is nobody's.

Is self-hosting required for GDPR compliance?

No. The GDPR requires a lawful basis, appropriate technical and organisational measures, and a valid transfer mechanism for any processing outside the EEA. A managed provider with EU-only residency and a solid DPA can meet all of that. Self-hosting is one way to satisfy the requirements — often the shortest path through a procurement review, because there is no third-party processor to assess — but it is not the only way.