Deployment & security

Runs where your data lives, including places nothing else is allowed to run

SetMeld supports a fully self-hosted deployment inside your own network and a managed deployment on SetMeld Cloud. Both share the same core components and workflow. The choice is driven by your security, compliance and operational requirements.

Model 1

Self-hosted

Every SetMeld component runs inside your on-premises environment or private cloud network. No data ever leaves your infrastructure. SetMeld Composer reasons about your data using an LLM of your choosing, hosted in the same network, so sensitive schema information and data samples are never transmitted to a third party.

YOUR ON-PREM / PRIVATE CLOUD NETWORKNo data leaves your network Source systemsDatabases · APIs · filesSetMeld ComposerReasons with your LLMSetMeld PipelineExtract · transform · resolveKnowledge graphUnified · governed · queryableConsumersBI · apps · agents · analysts
Every component, including SetMeld Composer, SetMeld Pipeline, the knowledge graph and the reasoning model, runs inside your own environment.

Designed for regulated buyers

Institutions with strict data residency requirements, where a third-party cloud is ruled out before the procurement conversation begins.

An LLM you have already approved

Bring the LLM your security team has already approved. SetMeld does not require a specific provider.

Full data sovereignty

Sources, graph, reasoning and query traffic all stay inside the boundary you already defend.

Model 2

SetMeld Cloud

Both components run in SetMeld Cloud and reason using an LLM that SetMeld operates. They connect to your siloed datasets over secure channels, scan them and extract data. The resulting knowledge graph is loaded back into your own network, so the authoritative unified store remains under your control and queries are served from that customer-resident graph.

YOUR NETWORKSETMELD CLOUD Source systemsDatabases · APIs · filesSetMeld ComposerReasons with SetMeld’s LLMSetMeld PipelineExtract · transform · resolveKnowledge graphUnified · governed · queryableConsumersBI · apps · agents · analysts
Both components run in SetMeld Cloud; the authoritative unified graph is still loaded back into your own network.

No compute to provision

You do not stand up infrastructure for SetMeld Composer, SetMeld Pipeline or a reasoning model.

Updates arrive automatically

Platform improvements land without an upgrade project.

The graph still lives with you

The unified store stays yours, in your network.

Controls

Governance controls

Access control

Permissions travel with the graph. Agents and applications inherit the same controls as the people who own the data.

Audit trails

Every transformation and every run is recorded, with timings, so you can reconstruct how a number came to exist.

Provenance

Datasource attribution is carried on every record and returned with every answer.

Data residency

Self-hosted deployments never transmit schema information or data samples outside your network.

No lock-in

Your source systems are untouched and the graph is yours. Leaving means turning SetMeld off.

FAQ

Deployment questions

Can we start on SetMeld Cloud and move on-prem later?
Yes. The components and the workflow are identical across models, and the schema you build is portable. Moving is a deployment change.
Does the LLM see our data?
In a self-hosted deployment the LLM is one you choose and host, inside your network, so nothing is transmitted to a third party. In SetMeld Cloud the reasoning model is operated by SetMeld, and scanning involves sending schema information and data samples to that environment over secure channels.
What is actually stored in the graph?
The unified, transformed records loaded from your sources, plus the ontology, the mappings, and the provenance metadata that lets any answer be traced back to its origin system.
Do you support air-gapped environments?
Self-hosted deployment is designed for exactly this shape of requirement. Talk to us about the specifics of your environment and we will tell you plainly what does and does not work.

Bring your security team to the first call

In the self-hosted model the architecture conversation is short, because every component runs inside your own network.